Log in

View Full Version : Form Mail Hijacking? Anyone have any info?


vonelab
2008-09-10, 02:08
Anyone know much about CGI form mail hijacking? I believe the method requires sending POST data over netcat to a vulnerable cgi mail script. Can anyone fill in anymore details?

O RLY
2008-09-10, 04:01
Dude.... you know the attack process. So, what's stopping you from learning more about it? Also, there are tons of CGI exploits for mail/login/random forms on websites. Usually they are used to insert code into a website, or other such things Even to the point of dumping sensitive passwords.


EDIT: This is kind of what you are looking for. It's outdated, but it's always good to have in your arsenal. Most people forget about stupid little bugs like this. http://insecure.org/sploits/test-cgi.html