读取 ASP 机密赚取 17,000 美元
samcurry.net | 博客 | #bug-bounty | #web-security | #path-traversal | #aspnet | #local-file-disclosure | #source-code-disclosure
摘要
从 ASP.NET 应用的本地文件泄露到 17,000 美元赏金:读出 download.aspx 源码、用特殊技巧绕过两点号遍历限制,进而利用扩大的访问面翻找服务器机密。
- 发布时间
- 收录时间
Skip to content