BugTraq
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 10 2013 02:52PM
Tobias Kreidl (tobias kreidl nau edu) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 10:44AM
Reindl Harald (h reindl thelounge net) (2 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 08:15PM
Stefan Kanthak (stefan kanthak nexgo de) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 08:53PM
Reindl Harald (h reindl thelounge net) (1 replies)


Am 11.08.2013 22:15, schrieb Stefan Kanthak:
> "Reindl Harald" <h.reindl (at) thelounge (dot) net [email concealed]> wrote:
>> Am 10.08.2013 16:52, schrieb Tobias Kreidl:
>>> It is for this specific reason that utilities like suPHP can be used as a powerful tool to at least keep the
>>> account user from shooting anyone but him/herself in the foot because of any configuration or broken security
>>> issues. Allowing suexec to anyone but a seasoned, responsible admin is IMO a recipe for disaster.
>>
>> and what makes you believe that a developer can not be a "seasoned, responsible admin"?
>
> Because developers write functions like "system", "symlink" and "suexec"
> which can create havoc (and are WELL-KNOWN for creating havoc since
> years) and allow everybody to call them in the default configuration of
> their software.

a so because some stupid developers all are faulty?

>> bullshit, many of the "seasoned, responsible admins" which are only
>> admins are unable to really understand the implications of whatever
>> config they rollout
>
> It was the developer who created and published this vulnerable software
> or the vulnerable default configuration in the first place.

it was the admin who did not RTFM and rolled out default
settings in environents with untrustable code

> If a user/administrator who installs software has to turn insecure
> features OFF its the developer who is to blame, and of course the
> testers, the QA and the management too

not entirely untrue, but anybody who thinks he can install
whatever server-software with defaults, not RTFM and call
hiself a serious admin is a fool

again:
symlinks are to not poision always and everywhere
they become where untrusted customer code is running
blame the admin which doe snot know his job and not
the language offering a lot of functions where some
can be misused

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlIH+eAACgkQhmBjz394Anm7agCeIW1sj1TQIGihsI2FqFdDdprd
VzMAoIJTKmYoaqCwRuXUmX+g2TVdOunb
=nab9
-----END PGP SIGNATURE-----

[ reply ]
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 09:56PM
Stefan Kanthak (stefan kanthak nexgo de) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 10:30PM
Reindl Harald (h reindl thelounge net) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 05:28PM
Coderaptor (coderaptor gmail com) (3 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 07:03PM
Jeffrey Walton (noloader gmail com)
RE: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 06:56PM
Peter Gregory (Peter Gregory tommybahama com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 06:11PM
Reindl Harald (h reindl thelounge net) (3 replies)
Re: Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 13 2013 10:26AM
Marco Floris (marco floris jaimeria org)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 10:42PM
Brandon M. Graves (bgraves slicer-net com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 12 2013 09:39PM
coderaptor (coderaptor gmail com)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 12:50PM
Ansgar Wiechers (bugtraq planetcobalt net) (1 replies)
Re: [Full-disclosure] Apache suEXEC privilege elevation / information disclosure Aug 11 2013 03:39PM
Reindl Harald (h reindl thelounge net)


 

Privacy Statement
Copyright 2010, SecurityFocus