MonkeyShell: using XML-RPC for access to a remote shell

看板FB_security作者時間21年前 (2004/10/11 09:00), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Security pundits have been warning about the dangers implicit with Web services for years. A good starting point for understanding the security issues related to Web services can be found at: http://searchwebservices.techtarget.com/originalContent/0,289142,sid26_gci872720,00.html Of course to really understand the security risks posed by Web services, you need to understand the basics of Web services. Enter an application I wrote called "Monkey Shell." MonkeyShell is a simple open source Python application that uses extensible markup language remote procedure calls (XML-RPC) to execute commands through a remote system shell. I kept the code terse (less than 100 lines total) so that it can be studied easily. It is similar to netcat except instead of "shell shoveling" data through a raw TCP connection, it wraps data in XML and transports it over HTTP. MonkeyShell is freely available at: http://www.sharp-ideas.net/ Cheers, Abe Usher, CISSP _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #11QTiY00 (FB_security)
文章代碼(AID): #11QTiY00 (FB_security)