[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: www.d.org insecure?



while the faq-o-matic certainly looks broken, it didn't look
particularly insecure.. mostly old html pages, config file stuff
related to FOM.  the maintenance "secret" is there for all
to see, so that should probably be changed.. but, assuming
the FOM itself checks input variables, it should be ok.

btw, http://www.debian.org/fom/config contains what i'd assume
to be the admin:
$adminAuth = 'csmall@debian.org';
$adminEmail = $adminAuth;

:)

On Wed, Dec 13, 2000 at 06:09:17AM -0500, xsdg wrote:
> 
> I went to <http://www.debian.org/fom> looking for that Faq-O-Matic, however, I found a directory listing with files that looked like they should be in /etc...I'm not sure who admins this server or I would have mailed them...
> 	--xsdg
> 
> -- 
>   ____________________________________________________________________________
>  / It is better to let one suspect that you are a fool than to open your mouth\
> {    and leave them no doubt.    http://xsdg.hypermart.net  xsdg@softhome.net  }
>  \____________________________________________________________________________/
> 
-- 
"... being a Linux user is sort of like living in a house inhabited
by a large family of carpenters and architects. Every morning when
you wake up, the house is a little different. Maybe there is a new
turret, or some walls have moved. Or perhaps someone has temporarily
removed the floor under your bed." - Unix for Dummies, 2nd Edition
        -- found in the .sig of Rob Riggs, rriggs@tesser.com



Reply to: