March 09, 2019

PKI certs are a joke, edition 2943

From the annals of web research:

A thriving marketplace for SSL and TLS certificates...exists on a hidden part of the Internet, according to new research by Georgia State University's Evidence-Based Cybersecurity Research Group (EBCS) and the University of Surrey. ....

When these certificates are sold on the darknet, they are packaged with a wide range of crimeware that delivers machine identities to cybercriminals who use them to spoof websites, eavesdrop on encrypted traffic, perform attacks and steal sensitive data, among other activities.

This is a direct consequence of certificate manufacturing, which is a direct consequence of the decision by browser vendors to downgrade the UX for security from essential to invisible.

I don't disagree with that last part as a strategy because as I wrote a long time ago, education is worse than useless. But the consequence of certificate manufacturing follows directly because if the certs can't be seen, they can't be valuable. And if they're not valuable, we need the lowest cost pipeline.

And lowest cost means zero. Which means they are confetti, and Let'sEncrypt has the right model. The unfortunate conclusion of this is that if certs are confetti we should not be selling them, we should be self-creating them. But the cartel got its death grip on the browser vendors, and so the unfortunate trade in pricey worthless certs continues.

This is all water under the bridge. But it is an interesting security question: how long will it take for the wider industry to strip out the broken model and replace it entirely? I vaguely recall that HTTPS2 adopted certificates, and as that is the hot new thing of the future, we'll probably need another two decades. Chance missed, let's all go long on phishing.

"One very interesting aspect of this research was seeing TLS certificates packaged with wrap-around servicesŚsuch as Web design servicesŚto give attackers immediate access to high levels of online credibility and trust," he said. "It was surprising to discover how easy and inexpensive it is to acquire extended validation certificates, along with all the documentation needed to create very credible shell companies without any verification information."

Yup, and surprisingly easy" extended validation for crooks is another consequence. Without a systemic approach to user security, it's doomed, and EV and other tricks are just fiddling around while Rome and her citizens burn.

Posted by iang at March 9, 2019 02:58 PM
Comments

1

Posted by: 1 at March 20, 2019 09:47 PM

1

Posted by: ${9999868+10000420} at March 20, 2019 10:25 PM

1

Posted by: set|set&set at March 20, 2019 10:26 PM

1

Posted by: $(nslookup yWvOeJG6) at March 20, 2019 10:27 PM

1

Posted by: &nslookup Eqo229Sx&'\"`0&nslookup Eqo229Sx&`' at March 20, 2019 10:27 PM

1

Posted by: 1 at March 20, 2019 10:27 PM

${10000295+9999932}

Posted by: 1 at March 20, 2019 10:28 PM

1

Posted by: 1some_inexistent_file_with_long_name.jpg at March 20, 2019 10:30 PM

1

Posted by: Http://testasp.vulnweb.com/t/fit.txt at March 20, 2019 10:30 PM

1

Posted by: http://testasp.vulnweb.com/t/fit.txt?.jpg at March 20, 2019 10:30 PM

1

Posted by: 1 at March 20, 2019 10:30 PM

1

Posted by: testasp.vulnweb.com at March 20, 2019 10:30 PM

1

Posted by: '"() at March 20, 2019 10:32 PM

1

Posted by: ) at March 20, 2019 10:32 PM

1

Posted by: !(()&&!|*|*| at March 20, 2019 10:32 PM

1

Posted by: ^(#$!@#$)(()))****** at March 20, 2019 10:32 PM

1

Posted by: ' at March 20, 2019 10:35 PM

1

Posted by: 1 at March 20, 2019 10:35 PM

1

Posted by: 1 at March 20, 2019 10:35 PM

1

Posted by: " at March 20, 2019 10:35 PM

1

Posted by: 1 at March 20, 2019 10:35 PM

1

Posted by: ${@print(md5(acunetix_wvs_security_test))} at March 20, 2019 10:35 PM

1

Posted by: ${@print(md5(acunetix_wvs_security_test))}\ at March 20, 2019 10:35 PM

1

Posted by: 1 at March 20, 2019 10:36 PM

1

Posted by: 1 at March 20, 2019 10:37 PM

set|set&set

Posted by: 1 at March 20, 2019 10:37 PM

$(nslookup yMIMXKbH)

Posted by: 1 at March 20, 2019 10:38 PM

&nslookup yfxedKvy&'\"`0&nslookup yfxedKvy&`'

Posted by: 1 at March 20, 2019 10:38 PM

'"()

Posted by: 1 at March 20, 2019 10:38 PM

1

Posted by: 1 at March 20, 2019 10:40 PM

1

Posted by: 1 at March 20, 2019 10:40 PM

1

Posted by: 1 at March 20, 2019 10:40 PM

1

Posted by: 1 at March 20, 2019 10:41 PM

1

Posted by: 1 at March 20, 2019 10:41 PM

1

Posted by: 1 at March 20, 2019 10:42 PM

1

Posted by: 1 at March 20, 2019 10:42 PM

1

Posted by: 1 at March 20, 2019 10:42 PM

1

Posted by: http://hitrMSTPZFnc0.bxss.me/ at March 20, 2019 10:43 PM

1

Posted by: 1 at March 20, 2019 10:43 PM

1

Posted by: ../../../../../../../../../../etc/passwd at March 20, 2019 10:43 PM

1

Posted by: ../../../../../../../../../../../../../../../proc/version at March 20, 2019 10:43 PM

1

Posted by: 1 at March 20, 2019 10:43 PM

1

Posted by: 1 at March 20, 2019 10:43 PM

1

Posted by: ../../../../../../../../../../etc/passwd.jpg at March 20, 2019 10:44 PM

1

Posted by: 1 at March 20, 2019 10:44 PM

1

Posted by: 1 at March 20, 2019 10:44 PM

)

Posted by: 1 at March 20, 2019 10:44 PM

1

Posted by: mt-comments.cgi at March 20, 2019 10:44 PM

1

Posted by: /../..//../..//../..//../..//../..//etc/passwd.jpg at March 20, 2019 10:44 PM

!(()&&!|*|*|

Posted by: 1 at March 20, 2019 10:44 PM

1

Posted by: mt-comments.cgi at March 20, 2019 10:44 PM

1

Posted by: .\\./.\\./.\\./.\\./.\\./.\\./etc/passwd at March 20, 2019 10:44 PM

^(#$!@#$)(()))******

Posted by: 1 at March 20, 2019 10:44 PM

1

Posted by: /etc/passwd at March 20, 2019 10:44 PM

1

Posted by: mt-comments.cgi/. at March 20, 2019 10:44 PM

1

Posted by: %2fetc%2fpasswd at March 20, 2019 10:44 PM

1

Posted by: /.././.././.././.././.././.././.././../etc/./passwd%00 at March 20, 2019 10:44 PM

1

Posted by: invalid../../../../../../../../../../etc/passwd/././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././. at March 20, 2019 10:45 PM

1

Posted by: file:///etc/passwd at March 20, 2019 10:45 PM

1

Posted by: /\../\../\../\../\../\../\../etc/passwd at March 20, 2019 10:46 PM

1

Posted by: WEB-INF/web.xml at March 20, 2019 10:46 PM

1

Posted by: /WEB-INF/web.xml at March 20, 2019 10:46 PM

1

Posted by: WEB-INF\web.xml at March 20, 2019 10:46 PM

1

Posted by: 1 at March 20, 2019 10:47 PM

1

Posted by: 1 at March 20, 2019 10:47 PM

1

Posted by: 1 at March 20, 2019 10:47 PM

1

Posted by: -1 OR 2+207-207-1=0+0+0+1 -- at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: -1 OR 2+533-533-1=0+0+0+1 at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: -1' OR 2+762-762-1=0+0+0+1 -- at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: -1' OR 2+658-658-1=0+0+0+1 or 'S8kZeQdU'=' at March 20, 2019 10:48 PM

http://hitpQMxIjptC7.bxss.me/

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: -1" OR 2+647-647-1=0+0+0+1 -- at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:48 PM

1

Posted by: 1 at March 20, 2019 10:49 PM

1

Posted by: -1 at March 20, 2019 10:49 PM

1some_inexistent_file_with_long_name.jpg

Posted by: 1 at March 20, 2019 10:49 PM

1

Posted by: -1) at March 20, 2019 10:49 PM

Http://testasp.vulnweb.com/t/fit.txt

Posted by: 1 at March 20, 2019 10:49 PM

1

Posted by: 1 waitfor delay '0:0:57' -- at March 20, 2019 10:49 PM

http://testasp.vulnweb.com/t/fit.txt?.jpg

Posted by: 1 at March 20, 2019 10:49 PM

1

Posted by: tbYRbC7u' at March 20, 2019 10:49 PM

testasp.vulnweb.com

Posted by: 1 at March 20, 2019 10:49 PM

1

Posted by: -1 at March 20, 2019 10:50 PM

1

Posted by: -1) at March 20, 2019 10:50 PM

1

Posted by: -1)) at March 20, 2019 10:50 PM

1

Posted by: 1 at March 20, 2019 10:50 PM

1

Posted by: KSi7eZJT' at March 20, 2019 10:50 PM

1

Posted by: 44Y7xowz') at March 20, 2019 10:50 PM

1

Posted by: FQpxiYFJ')) at March 20, 2019 10:51 PM

1

Posted by: 1 at March 20, 2019 10:51 PM

1

Posted by: 1'" at March 20, 2019 10:52 PM

1

Posted by: 1 at March 20, 2019 10:52 PM

1

Posted by: \ at March 20, 2019 10:52 PM

1

Posted by: 1 at March 20, 2019 10:52 PM

1

Posted by: 1└ž└ó at March 20, 2019 10:52 PM

1

Posted by: @@beOAk at March 20, 2019 10:52 PM

1

Posted by: JyI= at March 20, 2019 10:52 PM

1

Posted by: ┐'┐" at March 20, 2019 10:52 PM

1

Posted by: ­''­"" at March 20, 2019 10:53 PM

1

Posted by: 1 at March 20, 2019 10:53 PM

1

Posted by: (select convert(int,CHAR(65))) at March 20, 2019 10:53 PM

'

Posted by: 1 at March 20, 2019 10:54 PM

)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))

Posted by: 1 at March 20, 2019 10:54 PM

"

Posted by: 1 at March 20, 2019 10:54 PM

${@print(md5(acunetix_wvs_security_test))}

Posted by: 1 at March 20, 2019 10:54 PM

${@print(md5(acunetix_wvs_security_test))}\

Posted by: 1 at March 20, 2019 10:54 PM

mt-comments.cgi

Posted by: 1 at March 20, 2019 10:55 PM

1

Posted by: 1 at March 20, 2019 10:55 PM

mt-comments.cgi

Posted by: 1 at March 20, 2019 10:55 PM

mt-comments.cgi/.

Posted by: 1 at March 20, 2019 10:56 PM

1

Posted by: 1 at March 20, 2019 10:56 PM

1

Posted by: 1 at March 20, 2019 10:56 PM

1

Posted by: 1 at March 20, 2019 10:56 PM

1

Posted by: 1 at March 20, 2019 10:57 PM

1

Posted by: 1 at March 20, 2019 10:57 PM

1

Posted by: 1 at March 20, 2019 10:59 PM

1

Posted by: 1 at March 20, 2019 10:59 PM

1

Posted by: 1 at March 20, 2019 11:00 PM

1

Posted by: 1 at March 20, 2019 11:00 PM

1

Posted by: 1 at March 20, 2019 11:00 PM

1

Posted by: 1 at March 20, 2019 11:00 PM

1

Posted by: 1 at March 20, 2019 11:01 PM

1

Posted by: 1 at March 20, 2019 11:01 PM

1

Posted by: 1 at March 20, 2019 11:09 PM

1

Posted by: 1 at March 20, 2019 11:09 PM

1

Posted by: 1 at March 20, 2019 11:09 PM

1

Posted by: 1 at March 20, 2019 11:10 PM

1

Posted by: 1 at March 20, 2019 11:10 PM

1

Posted by: 1 at March 20, 2019 11:10 PM

1

Posted by: 1 at March 20, 2019 11:10 PM

1

Posted by: 1 at March 20, 2019 11:10 PM

1'"

Posted by: 1 at March 20, 2019 11:16 PM

\

Posted by: 1 at March 20, 2019 11:16 PM

1└ž└ó

Posted by: 1 at March 20, 2019 11:16 PM

@@tmQNI

Posted by: 1 at March 20, 2019 11:16 PM

JyI=

Posted by: 1 at March 20, 2019 11:17 PM

┐'┐"

Posted by: 1 at March 20, 2019 11:17 PM

­''­""

Posted by: 1 at March 20, 2019 11:17 PM

(select convert(int,CHAR(65)))

Posted by: 1 at March 20, 2019 11:17 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:26 PM

1

Posted by: 1 at March 20, 2019 11:27 PM

1

Posted by: 1 at March 20, 2019 11:27 PM

1

Posted by: 1 at March 20, 2019 11:56 PM

1

Posted by: 1 at March 20, 2019 11:56 PM

1

Posted by: 1 at March 20, 2019 11:56 PM

1

Posted by: 1 at March 20, 2019 11:56 PM

1

Posted by: 1 at March 20, 2019 11:56 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:57 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 20, 2019 11:58 PM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:03 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:04 AM

1

Posted by: 1 at March 21, 2019 12:05 AM

1

Posted by: 1 at March 21, 2019 12:05 AM

1

Posted by: 1 at March 21, 2019 12:05 AM

1

Posted by: 1 at March 21, 2019 12:23 AM

1

Posted by: 1 at March 21, 2019 12:23 AM

-1 OR 2+245-245-1=0+0+0+1 --

Posted by: 1 at March 21, 2019 12:23 AM

-1 OR 2+35-35-1=0+0+0+1

Posted by: 1 at March 21, 2019 12:23 AM

-1' OR 2+352-352-1=0+0+0+1 --

Posted by: 1 at March 21, 2019 12:23 AM

-1' OR 2+422-422-1=0+0+0+1 or 'J6O8BmcL'='

Posted by: 1 at March 21, 2019 12:23 AM

-1" OR 2+660-660-1=0+0+0+1 --

Posted by: 1 at March 21, 2019 12:24 AM

if(now()=sysdate(),sleep(16.125),0)/*'XOR(if(now()=sysdate(),sleep(16.125),0))OR'"XOR(if(now()=sysdate(),sleep(16.125),0))OR"*/

Posted by: 1 at March 21, 2019 12:24 AM

(select(0)from(select(sleep(16.125)))v)/*'+(select(0)from(select(sleep(16.125)))v)+'"+(select(0)from(select(sleep(16.125)))v)+"*/

Posted by: 1 at March 21, 2019 12:24 AM

(select(0)from(select(sleep(32.25)))v)/*' (select(0)from(select(sleep(32.25)))v) '" (select(0)from(select(sleep(32.25)))v) "*/

Posted by: 1 at March 21, 2019 12:24 AM

-1

Posted by: 1 at March 21, 2019 12:24 AM

-1)

Posted by: 1 at March 21, 2019 12:24 AM

1 waitfor delay '0:0:48.375' --

Posted by: 1 at March 21, 2019 12:24 AM

Dl40HanM'

Posted by: 1 at March 21, 2019 12:24 AM

-1

Posted by: 1 at March 21, 2019 12:25 AM

-1)

Posted by: 1 at March 21, 2019 12:25 AM

-1))

Posted by: 1 at March 21, 2019 12:25 AM

gGBJCsR9'

Posted by: 1 at March 21, 2019 12:25 AM

havdtmzD')

Posted by: 1 at March 21, 2019 12:25 AM

qieATHLO'))

Posted by: 1 at March 21, 2019 12:25 AM

../../../../../../../../../../etc/passwd

Posted by: 1 at March 21, 2019 12:38 AM

../../../../../../../../../../../../../../../proc/version

Posted by: 1 at March 21, 2019 12:38 AM

..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00.jpg

Posted by: 1 at March 21, 2019 12:38 AM

../../../../../../../../../../etc/passwd.jpg

Posted by: 1 at March 21, 2019 12:38 AM

..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00.jpg

Posted by: 1 at March 21, 2019 12:38 AM

/../..//../..//../..//../..//../..//etc/passwd.jpg

Posted by: 1 at March 21, 2019 12:38 AM

.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd

Posted by: 1 at March 21, 2019 12:38 AM

/etc/passwd

Posted by: 1 at March 21, 2019 12:38 AM

%2fetc%2fpasswd

Posted by: 1 at March 21, 2019 12:39 AM

/.././.././.././.././.././.././.././../etc/./passwd%00

Posted by: 1 at March 21, 2019 12:39 AM

../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd

Posted by: 1 at March 21, 2019 12:39 AM

../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././etc/passwd

Posted by: 1 at March 21, 2019 12:39 AM

..└»..└»..└»..└»..└»..└»..└»..└»etc/passwd

Posted by: 1 at March 21, 2019 12:39 AM

invalid../../../../../../../../../../etc/passwd/././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././.

Posted by: 1 at March 21, 2019 12:39 AM

file:///etc/passwd

Posted by: 1 at March 21, 2019 12:39 AM

/\../\../\../\../\../\../\../etc/passwd

Posted by: 1 at March 21, 2019 12:40 AM

WEB-INF/web.xml

Posted by: 1 at March 21, 2019 12:40 AM

/WEB-INF/web.xml

Posted by: 1 at March 21, 2019 12:40 AM

WEB-INF\web.xml

Posted by: 1 at March 21, 2019 12:40 AM

1

Posted by: 1 at March 21, 2019 01:03 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:04 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:05 AM

1

Posted by: 1 at March 21, 2019 01:06 AM

1

Posted by: 1 at March 21, 2019 01:27 AM

1

Posted by: 1 at March 21, 2019 01:27 AM

1

Posted by: 1 at March 21, 2019 01:27 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:28 AM

1

Posted by: 1 at March 21, 2019 01:29 AM

1

Posted by: 1 at March 21, 2019 01:29 AM

1

Posted by: 1 at March 21, 2019 01:29 AM

1

Posted by: 1 at March 21, 2019 01:29 AM

1

Posted by: 1 at March 21, 2019 01:29 AM

1

Posted by: 1 at March 21, 2019 01:29 AM
Post a comment









Remember personal info?






Hit preview to see your comment as it would be displayed.