Re: Another flaw in Apache?
From: Jedi/Sector One (j@pureftpd.org)Date: 06/23/02
- Previous message: Filipe Jorge Marques de Almeida: "Re: Another flaw in Apache?"
- In reply to: Filipe Jorge Marques de Almeida: "Re: Another flaw in Apache?"
- Next in thread: Michal Zalewski: "Re: Another flaw in Apache?"
- Next in thread: Jedi/Sector One: "Re: Another flaw in Apache?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 23 Jun 2002 16:05:16 +0200 From: Jedi/Sector One <j@pureftpd.org> To: Filipe Jorge Marques de Almeida <filipe@rnl.ist.utl.pt>
On Sun, Jun 23, 2002 at 03:03:13PM +0100, Filipe Jorge Marques de Almeida wrote:
> Don't forget this is not a serious vulnerability in many configurations (if the
> user already has permission to run cgi scripts without suexec, SSI, etc).
Indeed, the fact that any user can stop the whole web server, or launch
commands as the web server uid despite the use of suexec is not serious.
-- __ /*- Frank DENIS (Jedi/Sector One) <j@42-Networks.Com> -*\ __ \ '/ Secure FTP Server \' / \/ Misc. free software \/
- Previous message: Filipe Jorge Marques de Almeida: "Re: Another flaw in Apache?"
- In reply to: Filipe Jorge Marques de Almeida: "Re: Another flaw in Apache?"
- Next in thread: Michal Zalewski: "Re: Another flaw in Apache?"
- Next in thread: Jedi/Sector One: "Re: Another flaw in Apache?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|