5 ms·
Being as confusing as possible actually seems like a really good tactic. Depending on the web server and frameworks installed, couldn't etc/shadow.php actually
by dmux 4y ago
Being as confusing as possible actually seems like a really good tactic. Depending on the web server and frameworks installed, couldn't etc/shadow.php actually be a file in a common framework? Also, if I wanted to be extra obscure, "redirect=google.com" wouldn't actually do what you think it would. It's just a key and a value which could be used for who-knows-what internally.
- yamtaddle 4y ago/etc/shadow is a file containing system account info that should never be accessible to the public on a properly-configured webserver. It's possible the request was probing for some very-specific combo of misconfigurations that might permit reading sensitive files, without going so far as to request the sensitive file.
- dmux 4y agoRight, I understand that. What I probably should have made more clear was whether it was trying to get to /etc/shadow, or another .../etc/shadow.php file located somewhere within the web-server's file directory.