[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] More Cobalt Hacks



> However, it can be enabled by any user with a one line .htaccess file
> (as can CGI).  With that, you can also gain shell access.
...
> They denied telnet access to all users except root (I think)

The point is that the shell access is delivered over port 80.

They've opened a shell over the data stream normally used to request and
deliver web pages.

-HJC
"All the world's a file system and all the users merely browsers."