Re: [Full-disclosure] Apache suEXEC privilege elevation / inform

看板Bugtraq作者時間12年前 (2013/08/11 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/32 (看更多)
--1wO6MifTVGqKnIr6PNAiMDgfLI80OWIIj Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Am 10.08.2013 12:10, schrieb Gichuki John Chuksjonia: > One thing u gotta remember most of the Admins who handle webservers in > a network are also developers since most of the organizations will > always need to cut on expenses, and as we know, most of the developers > will just look into finishing work and making it work. So if something > doesn't run due to httpd.conf, you will find these guys loosening > server security, therefore opening holes to the infrastructure. i am one of the developers who are admin why? because maintaining servers where only internal developed software gives you the power to make security as tighten as possible - and yes security is *always* first not the admins which are developers are the problem crap like wordpress, joomla, phpBB is the problem because these developers have no idea how to secure maintain a server and try to develop software which can be installed by any random fool on whatever webserver without understand the implications thats's why these applications are *strictly* forbidden on any machine i am responsible for, it's enough to write abuse mails each time one of these installations outside got hacked and is starting attacks on 3rd parties --1wO6MifTVGqKnIr6PNAiMDgfLI80OWIIj Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iEYEARECAAYFAlIGTXMACgkQhmBjz394AnnXagCfbwWx8lhcpGCZicxcmW4neZtL IAcAoJgYrZpKHIivn4H/+7WjcFAIMYuX =6jTx -----END PGP SIGNATURE----- --1wO6MifTVGqKnIr6PNAiMDgfLI80OWIIj--
文章代碼(AID): #1I1d_XGE (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 4 之 32 篇):
文章代碼(AID): #1I1d_XGE (Bugtraq)