Vulnerability Development mailing list archives
Re: Another flaw in Apache?
From: Michal Zalewski <lcamtuf () bos bindview com>
Date: Sun, 23 Jun 2002 10:13:32 -0400 (EDT)
On Sun, 23 Jun 2002, Filipe Jorge Marques de Almeida wrote:
Don't forget this is not a serious vulnerability in many configurations (if the user already has permission to run cgi scripts without suexec, SSI, etc).
Not exactly. You are having access to the httpd child process, not a spawned CGI script. This means that you control some interesting goods, such as file descriptors, or... oh well, the child process itself. Think about serving spoofed contents to all requests? Besides, suexec is pretty popular nowadays. -- _____________________________________________________ Michal Zalewski [lcamtuf () bos bindview com] [security] [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};: =-=> Did you know that clones never use mirrors? <=-= http://lcamtuf.coredump.cx/photo/
Current thread:
- Re: Another flaw in Apache?, (continued)
- Re: Another flaw in Apache? Alexander Yurchenko (Jun 22)
- RE: Another flaw in Apache? Ryan Sweat (Jun 22)
- Re: Another flaw in Apache? Michal Zalewski (Jun 22)
- Re: Another flaw in Apache? Jedi/Sector One (Jun 23)
- Re: Another flaw in Apache? Filipe Jorge Marques de Almeida (Jun 23)
- Re: Another flaw in Apache? Jedi/Sector One (Jun 23)
- Message not available
- Re: Another flaw in Apache? Filipe Almeida (Jun 23)
- Re: Another flaw in Apache? Alexander Yurchenko (Jun 23)
- Re: Another flaw in Apache? Jedi/Sector One (Jun 23)
- Re: Another flaw in Apache? Michal Zalewski (Jun 23)
- Re: Another flaw in Apache? Alexander Yurchenko (Jun 22)
- Re: Another flaw in Apache? Michal Zalewski (Jun 23)
- Re: Another flaw in Apache? sd (Jun 26)