best language for 3D manipulation over web ?
TGOS
tgos at spamcop.net
Thu Jun 7 15:21:10 EDT 2001
On Thu, 7 Jun 2001 19:46:28 +0200, "Boyd Roberts" <boyd at insultant.net> wrote:
> "TGOS" <tgos at spamcop.net> a écrit dans le message news: e03vhto1hehnstnnaj7ekru67lulnrme8v at 4ax.com...
>>
>> Now you can get Sendmail executing a command for you, like "bash" and this bash
>> is then a root shell, because it was invoked by a root process.
>
> in your dreams. modern sendmails are very resistant to attack.
I didn't say that this will still work today, I was just repeating what I found
a page with a collection of (meanwhile fixed) Sendmail bugs.
> it doesn't need to run as root, except to bind to port 25 and
> then it can setuid to some 'mail' user.
The fact that it doesn't have to root as root process is something I mentioned
as well (actually I found a whole webpage about this topic).
--
TGOS
More information about the Python-list
mailing list