Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] hello from a new / old member
- Date: Fri, 10 Mar 2006 00:31:31 +0900
- From: "Stephen J. Turnbull" <stephen@example.com>
- Subject: Re: [tlug] hello from a new / old member
- References: <1141877845.12967.107.camel@example.com><87ek1culi6.fsf@example.com><20060309104207.68c62a9b.godwin.stewart@example.com>
- Organization: The XEmacs Project
- User-agent: Gnus/5.1007 (Gnus v5.10.7) XEmacs/21.5-b23 (linux)
>>>>> "Godwin" == Godwin Stewart <godwin.stewart@example.com> writes: Godwin> Note that the vulnreability isn't in PHP itself but in Godwin> software written in PHP that doesn't perform adequate Godwin> sanity checks before utilising the data posted to it. This Godwin> has all too often been the case (phpBB anyone?) Well, I'm seeing about a dozen different ooh-do-me-do-me.php URLs. So I think the vulnerability is the use of PHP. Cf. http://turnbull.sk.tsukuba.ac.jp/Tools/Attitude/elitism.html Godwin> Security by obscurity isn't always the best solution but Godwin> it appears to work here. Run sshd on a non-standard port Godwin> and have done with it. Oh, I'm curious to see who knocks; I just don't need to know how many different accounts/passwords they've managed to collect to date. Among other things, I've smushed 3 roaches in colleagues' machines. -- School of Systems and Information Engineering http://turnbull.sk.tsukuba.ac.jp University of Tsukuba Tennodai 1-1-1 Tsukuba 305-8573 JAPAN Ask not how you can "do" free software business; ask what your business can "do for" free software.
- Follow-Ups:
- Re: [tlug] hello from a new / old member
- From: Godwin Stewart
- References:
- [tlug] hello from a new / old member
- From: Scott VanDusen
- Re: [tlug] hello from a new / old member
- From: Stephen J. Turnbull
- Re: [tlug] hello from a new / old member
- From: Godwin Stewart
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] hello from a new / old member
- Next by Date: Re: [tlug] hello from a new / old member
- Previous by thread: Re: [tlug] hello from a new / old member
- Next by thread: Re: [tlug] hello from a new / old member
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links