[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] [Raq4] Directory Listing Exploit found.



> ** Having said all that, if you email me (and I can spot your emails from
> the filtered cobalt list) then I'll probably send you the script to use at
> your own risk, since it might save you the time of looking up how
> to do it,
> and is an education to how simple it is to look into a server you host -
> without the need for fancy exploits, admin passwords or shell access.
>
> Regards,
> Jonathan Michaelson

Jonathon - I run a small web hosting company with a couple of RaQs and
security is always a worry to me one 'cos I don't do it as my main job and
therefore don't spend enough time on it and secondly as all my customers are
very unknowledgable but read the magazines etc and then try and play (with
their live site) leaving me to pick up the pieces.

I am not a perl programmer - I hack at php but would not class myself as a
programmer although I do run www.cobaltworld.com as I used to work at
Cobalt.  I would be very grateful of the script to use to test my own RaQs
only and for administrative purposes.

Regards

Gavin