<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Local File Inclusion with Magic_quotes_gpc enabled</title>
	<atom:link href="http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/</link>
	<description>From Pentesters To Pentesters</description>
	<lastBuildDate>Thu, 08 Jul 2010 02:17:27 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: 7b-ly.com</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-96702</link>
		<dc:creator>7b-ly.com</dc:creator>
		<pubDate>Mon, 24 May 2010 20:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-96702</guid>
		<description>i did try whit etc/passwd%00 
but that does not work
any ideal ?</description>
		<content:encoded><![CDATA[<p>i did try whit etc/passwd%00<br />
but that does not work<br />
any ideal ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Week 5 in Review &#124; Infosec Events</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94604</link>
		<dc:creator>Week 5 in Review &#124; Infosec Events</dc:creator>
		<pubDate>Mon, 08 Feb 2010 14:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94604</guid>
		<description>[...] Local File Inclusion with Magic_quotes_gpc enabled &#8211; notsosecure.com Penetration using magic_quote_gpc and PHP [...]</description>
		<content:encoded><![CDATA[<p>[...] Local File Inclusion with Magic_quotes_gpc enabled &#8211; notsosecure.com Penetration using magic_quote_gpc and PHP [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94376</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Wed, 03 Feb 2010 06:16:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94376</guid>
		<description>Similar stuff is possible on linux: http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/</description>
		<content:encoded><![CDATA[<p>Similar stuff is possible on linux: <a href="http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/" rel="nofollow">http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sid</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94331</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Tue, 02 Feb 2010 16:16:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94331</guid>
		<description>Hi skully, please see the update, you dont need magic quote at all. I managed to make so many mistakes in a small blog post :(
</description>
		<content:encoded><![CDATA[<p>Hi skully, please see the update, you dont need magic quote at all. I managed to make so many mistakes in a small blog post <img src='http://www.notsosecure.com/folder2/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: skully</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94329</link>
		<dc:creator>skully</dc:creator>
		<pubDate>Tue, 02 Feb 2010 16:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94329</guid>
		<description>Hi,
Very interesting only I am not able to reproduce it. I tested from 100 to &gt; 4096 dots, this does not disable the NULL byte from being escaped.

You say you tested on WAMP ? ie: Windows ? How can /etc/passwd work on windows ?

I tried in windows also, and it failed. Could you please explain or give poc code ?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Very interesting only I am not able to reproduce it. I tested from 100 to &gt; 4096 dots, this does not disable the NULL byte from being escaped.</p>
<p>You say you tested on WAMP ? ie: Windows ? How can /etc/passwd work on windows ?</p>
<p>I tried in windows also, and it failed. Could you please explain or give poc code ?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sid</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94321</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Tue, 02 Feb 2010 12:18:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94321</guid>
		<description>Hi Bogan,

i have only tested it on windows, while the backslash(\) will get escaped by magic quote the forward slash will not be escaped, so that explains why it will only work if include is relational in windows.

&lt;del datetime=&quot;2010-02-02T12:39:39+00:00&quot;&gt;I can confirm that in my windows setup, it worked with null byte&lt;/del&gt;. As you pointed out, it doesn&#039;t work with null byte and the null byte is actually not required.</description>
		<content:encoded><![CDATA[<p>Hi Bogan,</p>
<p>i have only tested it on windows, while the backslash(\) will get escaped by magic quote the forward slash will not be escaped, so that explains why it will only work if include is relational in windows.</p>
<p><del datetime="2010-02-02T12:39:39+00:00">I can confirm that in my windows setup, it worked with null byte</del>. As you pointed out, it doesn&#8217;t work with null byte and the null byte is actually not required.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan Calin</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94320</link>
		<dc:creator>Bogdan Calin</dc:creator>
		<pubDate>Tue, 02 Feb 2010 12:13:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94320</guid>
		<description>No, it&#039;s not about the null byte. It works like this vuln.php?page=../../../../../etc/passwd....(lots of dots). With the null byte it doesn&#039;t work.

It only works on Windows AND it only works if the include is relative.

If you have something like: 
include &quot;d:\\xampp\\htdocs\\test\\&quot; . $_GET[&#039;i&#039;] . &quot;.txt&quot;; it doesn&#039;t work.</description>
		<content:encoded><![CDATA[<p>No, it&#8217;s not about the null byte. It works like this vuln.php?page=../../../../../etc/passwd&#8230;.(lots of dots). With the null byte it doesn&#8217;t work.</p>
<p>It only works on Windows AND it only works if the include is relative.</p>
<p>If you have something like:<br />
include &#8220;d:\\xampp\\htdocs\\test\\&#8221; . $_GET['i'] . &#8220;.txt&#8221;; it doesn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: s3th</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94319</link>
		<dc:creator>s3th</dc:creator>
		<pubDate>Tue, 02 Feb 2010 12:04:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94319</guid>
		<description>i wanna see a printscreen :)</description>
		<content:encoded><![CDATA[<p>i wanna see a printscreen <img src='http://www.notsosecure.com/folder2/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bernardo</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94318</link>
		<dc:creator>Bernardo</dc:creator>
		<pubDate>Tue, 02 Feb 2010 11:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94318</guid>
		<description>Good one Sid!</description>
		<content:encoded><![CDATA[<p>Good one Sid!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
