12
HTTP CGI directory cgi-bin found
HTTP
2003/11/13
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
2.0
Corrected the plugin structure and added the accuracy values in 1.3. Improved the pattern matching and added the changelog in 2.0
tcp
80
open|send GET /cgi-bin HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/#.# 200 *
98
This plugin was written with the ATK Attack Editor.
Web servers with a default cgi-bin directory.
Web servers without the default cgi-bin directory.
Configuration
An attacker can try to reach /cgi-bin as a possible directory for CGI scripts. If he gets an Found message he could determine that this directory exists and is used. This information can be used for further attempts.
Do not allow users to get the directory listing of the cgi directory.
30 minutes
Yes
Yes
Yes
Low
8
8
4
5
Medium
Many CGI and security scanners are able to do the same or a similar check.
10039
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch