[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: NeverEverNoSanity WebWorm???????



On Tue, 2004-12-21 at 11:43 +1300, Simon Buchanan wrote:
[snip] 
> this is wierd, you cant ssh into the box. its got pureftpd/apache/php/mysql 
> running on it. with only ftp/http ports open, all else firewalled out....

So, either:
a) there's a root-exploitation bug in pureftpd
b) there's a root-exploitation bug in apache
c) there's a root-exploitation bug in php
d) you misconfigured pureftpd
e) you misconfigured apache
e) you misconfigured php

Why are you using an ftpd on a development box?  That's a major 
sin right there.

-- 
-----------------------------------------------------------------
Ron Johnson, Jr.
Jefferson, LA USA
PGP Key ID 8834C06B I prefer encrypted mail.

"The main reason that M$ gets bashed is that they persist in
writing bad code, on top of bad code.... As many have said, there
is NO PERFECT OS. The better OS though, IMHO, is the one that
will openly deal with issues, both major, and minor. Microsoft
still needs a lot of work in this area."
http://www.securityfocus.com/columnists/202/comment/24104#MSG


Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: