Tenon Intersystems Please see text links at bottom of page for navigation
Please see text links at bottom of page for navigation

Search tenon.com

Thanks to:

WebTen

Re: Apache Vulnerability in WebTen

To: <webten@xxxxxxxxxxxxxxx>
Subject: Re: Apache Vulnerability in WebTen
From: Erik Lotspeich <erik@xxxxxxxxx>
Date: Mon, 24 Jun 2002 14:48:51 -0700 (PDT)
On Mon, 24 Jun 2002, Robert Brandtjen wrote:

> On Monday 24 June 2002 04:25 pm, you wrote:
> > It's not a matter of whether or not WebTen has certain "commands"
> > available.  It would be certainly possible for a hacker to "install"
> > certain commands on a victimized system in the /tmp directory (to which
> > all users have access), and run them.  Since any installed command could
> > only be run by user nobody, damage would be limited.
>
> hehe, not likely, unless you mean some perl scripts, see, binaries for unix
> wont run on just any old unix machine, they have to be compiled for that
> particular distro - and last I checked, webten had no such app as GCC
> installed with it to compile apps. a Mac will not let you run apps from just
> anywhere, it has no concept of root. installing a program on a mac would
> require the installation of an applescript which would then know to install
> what where.

You're forgetting about MachTen! ;)

Erik.

-- 
Erik Lotspeich                          Lead Engineer
Tenon Intersystems                      erik@xxxxxxxxx
1123 Chapala Street Ste 200             805-963-6983
Santa Barbara, CA 93101-3142            http://www.tenon.com/


| Tenon Home | Products | Order | Contact Us | About Tenon | Register | Tech Support | Resources | Press Room | Mailing Lists |

Powered By iTools

Copyright©2003 Tenon Intersystems, 232 Anacapa Street, Suite 2A, Santa Barbara, CA 93101. All rights reserved.
Questions about our website - Contact: webmaster@tenon.com.


Tenon Home  Tenon Home  Tenon Home  Tenon Home Product Info  Tenon Ordering Contact About Register Support Resources Press Mailing Lists