The WinGate log service is configured by default to only allow connections from 127.0.0.1, but can be set to allow connections from anywhere. Either way, there is a vulnerability that will allow any file to be read through the log service port over an http connection. Update (October 16, 2000): Blue Panda <bluepanda@dwarf.box.sk> has discovered that a variation of the vulnerability exists in recent versions. Using escaped characters, one can achieve the same effect.
The WinGate log service is configured by default to only allow connections from 127.0.0.1, but can be set to allow connections from anywhere. Either way, there is a vulnerability that will allow any file to be read through the log service port over an http connection. Update (October 16, 2000): Blue Panda <bluepanda@dwarf.box.sk> has discovered that a variation of the vulnerability exists in recent versions. Using escaped characters, one can achieve the same effect.