Re: Possible exploit?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 2/12/2014 13:11, rahul bhola wrote:
by sanitize i mean just check that u dont directly put the data coming
from cmd or command to exec() or functions that might compromise the
security of your system.

Are you talking about in CGI programs?

 By url i mean example:
yoursite.com/sid=XXXXXXXXXXXXXXXXXXXXXXXXXXXX&shopid=
<http://yoursite.com/sid=XXXXXXXXXXXXXXXXXXXXXXXXXXXX&shopid=>http://www.google.com/humans.txt?
would show you what he got

If I do the above I get a File Not Found (404). I think there must be more to it than that.

--

Knute Johnson

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx





[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux