in reply to Re: •Re: Shell Simulation via CGI
in thread Shell Simulation via CGI
Of course, its still a massive security hole, and I wouldn't be surprised if most hosts deny it in their service agreements.I'd be surprised if you could distinguish this tool from another CGI script in any legally binding way.
There's no escalation of privilege for me as the CGI uploader, because I can already write scripts that do what I need, albeit not interactively.
If you're referring to the insecurity of an unsecured CGI script, that insecurity already exists in many scripts, such as the early Matt Wright attempts.
So, I don't get this "massive security hole" you speak of.
-- Randal L. Schwartz, Perl hacker
Be sure to read my standard disclaimer if this is a reply.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: •Re: Re: •Re: Shell Simulation via CGI
by jryan (Vicar) on Feb 05, 2003 at 01:40 UTC | |
by Aristotle (Chancellor) on Feb 06, 2003 at 13:20 UTC | |
by jryan (Vicar) on Feb 06, 2003 at 21:43 UTC | |
by Aristotle (Chancellor) on Feb 07, 2003 at 12:54 UTC |