[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Security bug (knock on wood!)



on 6/28/00 1:54 PM, Fathi Said at fathi@xxxxxx wrote:

> Hey,
> 
> Some other subscriber of this list just sent me that link:
> http://black.box.sk/issue.php3?article=cobalt.txt&issue=9
> 
> Have these problems already been elimitated in existing upgrades?
> I hope so.

I don't think that the Raq2's ship with SSI enabled.  In fact I am nearly
positive that they don't.  But it looks pretty dangerous for a Raq3.

These hacks require that you have existing access to the machine, as well.

These are both good reasons why I don't like to use shared servers, and why
it is important to lock down unnecessary features on your machine.

-k