Here we go again - ISP DPI, but is it interception?

Chris Edwards chris-ukcrypto at lists.skipnote.org
Fri Jul 30 17:06:18 BST 2010


On Fri, 30 Jul 2010, Peter Fairbrother wrote:

| I don't get it.
| 
| If I want to find out whether a site allows directory traversal - some sites
| do, some don't - how else am I going to find out other than adding a "/.." ?

And it seems the tsunami hacker didn't even add "/.."

- he simply truncated the URL, to find a parent or root page.

Which seems even more unlikey to do damage!




More information about the ukcrypto mailing list