Re: Another flaw in Apache?

From: Michal Zalewski (lcamtuf@bos.bindview.com)
Date: 06/23/02


Date: Sun, 23 Jun 2002 10:13:32 -0400 (EDT)
From: Michal Zalewski <lcamtuf@bos.bindview.com>
To: Filipe Jorge Marques de Almeida <filipe@rnl.ist.utl.pt>

On Sun, 23 Jun 2002, Filipe Jorge Marques de Almeida wrote:

> Don't forget this is not a serious vulnerability in many configurations
> (if the user already has permission to run cgi scripts without suexec,
> SSI, etc).

Not exactly. You are having access to the httpd child process, not a
spawned CGI script. This means that you control some interesting goods,
such as file descriptors, or... oh well, the child process itself. Think
about serving spoofed contents to all requests? Besides, suexec is pretty
popular nowadays.

-- 
_____________________________________________________
Michal Zalewski [lcamtuf@bos.bindview.com] [security]
[http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};:
=-=> Did you know that clones never use mirrors? <=-=
          http://lcamtuf.coredump.cx/photo/