Vulnerability Development mailing list archives

Re: CGIs running on Windows


From: "Bluefish (P.Magnusson)" <11a () GMX NET>
Date: Tue, 10 Oct 2000 09:08:23 +0200

open FILE, "$some_user_controllable_input;
is secure on a machine running Windows? At least on
machine
running *nix it would be a big security hole.

I've unsure if you can do something weird here, like trying things like "|
command" and so; someone tried? But anyway, it's a big security hole if
the server has readable files which shouldn't be exposed to the internet.

As for windows programmers being more careless, perhaps youy should
refrase it as more clueless ;-)

..:::::::::::::::::::::::::::::::::::::::::::::::::..
     http://www.11a.nu || http://bluefish.11a.nu
    eleventh alliance development & security team

             http://www.eff.org/cafe


Current thread: