Joomla 1.0.13 - 1.0.14 / (remote) PHP file inclusion possible if old configuration.php

2008-02-14 Thread Hendrik Jan Verheij
ON by using the line in configuration.php-dist in configuration.php: if(!defined('RG_EMULATION')) { define( 'RG_EMULATION', 0 ); } // Off by default for security Regards, Hendrik-Jan Verheij BWSS B.V.

Re: bugtraq id 2173 Lotus Domino Server

2001-01-09 Thread Hendrik-Jan Verheij
/nonexistingdir/.nsf/../../fileyouwanttoget This makes the url redirection solution less obvious to guess, but it still leaves you vulnerable.   Regards,   Hendrik-Jan Verheij  http://redheat.orgHostmaster Popin Internet    +3174 2555770[EMAIL PROTECTED]    http://www.popin.nlAssimilation is

Re: Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root

2001-01-09 Thread Hendrik-Jan Verheij
after it's discovery. regards, Hendrik-Jan Verheij http://redheat.org Hostmaster Popin Internet+31074 2555660 [EMAIL PROTECTED]http://www.popin.nl Assimilation is irrelevant, You are futile! - Original Message - From: "Ben Greenbaum" <[EMAIL PROTECTED]> To: <[EMAI