Tomcat 6 Missing Host Header Internal IP Address Disclosure

Source: Internet
Author: User
Tags apache tomcat

The information leakage vulnerability may expose sensitive information about the system or Web application to attackers. Attackers can use this information to learn more about the system during unauthorized access.
 
This security problem exists in Microsoft's IIS 4.0, 5.0, and 5.1, and has been solved in IIS6. I encountered this problem for the first time in tomcat.
Details: Tomcat 6 lacks the internal IP address of the Host header.
 
Test Version: Apache Tomcat Version 6.0.35, Nov 28 2011
 
The leaked Intranet address is 10.0.0.20.

Www.2cto.com
GET/corp HTTP/1.0
 
 
HTTP/1.1 302 Moved Temporarily
 
Server: Apache-Coyote/1.1
 
Location: http: // 10.0.0.20/corp/
 
Date: Tue, 03 Jul 2012 05:49:52 GMT
 
Connection: close
Solution:
And so on.

Author akast

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.