Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
GHH Portal 1.1 (passwd.txt) Remote Password Disclosure Vulnerability Apr 30 2007 11:10AM
crazy_king eno7 org (1 replies)
Re: GHH Portal 1.1 (passwd.txt) Remote Password Disclosure Vulnerability Apr 30 2007 04:20PM
Jamie Riden (jamie riden gmail com)
On 30 Apr 2007 11:10:51 -0000, crazy_king (at) eno7 (dot) org [email concealed] <crazy_king (at) eno7 (dot) org [email concealed]> wrote:
> By Cr@zy_King
>
> crazy_king (at) eno7 (dot) org [email concealed]
>
> Biyosecurity.Net & Expw0rm.Com
>
> Thanks : Liz0 & DarkXBoyZ & Eno7 & ApAci & Uyuss & Crackers_Child & Th3_43k1R & Xoron & Ajannn
>
> Portal : GHH

Hi there,

GHH is a honeypot, not a portal, and it is meant to expose this
information. The file passwd.txt is actually a PHP script which
generates a random password.
http://ghh.sourceforge.net/introduction.php describes briefly how GHH works.

cheers,
Jamie
--
Jamie Riden, CISSP / jamesr (at) europe (dot) com [email concealed] / jamie (at) honeynet.org (dot) uk [email concealed]
UK Honeynet Project: http://www.ukhoneynet.org/

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus