Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Related to this bug: used to be a vulnerability in IIS back in the late 90s where you could append ::$DATA to a file name (e.g Foo.asp::$DATA) and download a server-side script's source code.


Related - meaning the ::$DATA was interpreted as a request for an alternate data stream from the file, and then read the default stream?


More info https://technet.microsoft.com/en-us/library/security/ms98-00... - seems to imply that $DATA is the default stream.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: