BugTraq
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 10 2013 02:52PM
Tobias Kreidl (tobias kreidl nau edu) (1 replies)
It is for this specific reason that utilities like suPHP can be used as
a powerful tool to at least keep the account user from shooting anyone
but him/herself in the foot because of any configuration or broken
security issues. Allowing suexec to anyone but a seasoned, responsible
admin is IMO a recipe for disaster.
--Tobias

On 8/10/2013 7:25 AM, Reindl Harald wrote:
>
> Am 10.08.2013 12:10, schrieb Gichuki John Chuksjonia:
>> One thing u gotta remember most of the Admins who handle webservers in
>> a network are also developers since most of the organizations will
>> always need to cut on expenses, and as we know, most of the developers
>> will just look into finishing work and making it work. So if something
>> doesn't run due to httpd.conf, you will find these guys loosening
>> server security, therefore opening holes to the infrastructure.
> i am one of the developers who are admin
>
> why?
>
> because maintaining servers where only internal developed
> software gives you the power to make security as tighten
> as possible - and yes security is *always* first
>
> not the admins which are developers are the problem
>
> crap like wordpress, joomla, phpBB is the problem because
> these developers have no idea how to secure maintain a
> server and try to develop software which can be installed
> by any random fool on whatever webserver without understand
> the implications
>
> thats's why these applications are *strictly* forbidden
> on any machine i am responsible for, it's enough to write
> abuse mails each time one of these installations outside
> got hacked and is starting attacks on 3rd parties
>

[ reply ]
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 10:44AM
Reindl Harald (h reindl thelounge net) (2 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 08:15PM
Stefan Kanthak (stefan kanthak nexgo de) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 08:53PM
Reindl Harald (h reindl thelounge net) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 09:56PM
Stefan Kanthak (stefan kanthak nexgo de) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 10:30PM
Reindl Harald (h reindl thelounge net) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 05:28PM
Coderaptor (coderaptor gmail com) (3 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 07:03PM
Jeffrey Walton (noloader gmail com)
RE: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 06:56PM
Peter Gregory (Peter Gregory tommybahama com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 06:11PM
Reindl Harald (h reindl thelounge net) (3 replies)
Re: Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 13 2013 10:26AM
Marco Floris (marco floris jaimeria org)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 10:42PM
Brandon M. Graves (bgraves slicer-net com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 09:39PM
coderaptor (coderaptor gmail com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 12:50PM
Ansgar Wiechers (bugtraq planetcobalt net) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 03:39PM
Reindl Harald (h reindl thelounge net)


 

Privacy Statement
Copyright 2010, SecurityFocus