Apache and suexec issue that wont let me run my python script
Νικόλαος Κούρας
nikos.gr33k at gmail.com
Wed Jun 5 05:32:27 EDT 2013
Τη Τετάρτη, 5 Ιουνίου 2013 12:27:20 μ.μ. UTC+3, ο χρήστης Chris Angelico έγραψε:
> On Wed, Jun 5, 2013 at 7:14 PM, Νικόλαος Κούρας <nikos.gr33k at gmail.com> wrote:
>
> > NEXT THIS YOU'RE GONNA TELL ME IS TO BE HAPPY THAT YOU DIDN'T WIPE THE WHOLE SYSTEM OUT BY 'RM -RF /'
>
>
>
> Yes. Actually, yes. Do you understand now what you have done by giving
>
> your password to multiple people? This is *completely* different from
>
> asking for help. You are giving someone complete access to do ANYTHING
>
> and without even being logfiled (try it - can you find out what I did?
>
> You'll be able to find a few things, like what IP addresses I logged
>
> in from, but not everything); this is something that you simply do not
>
> EVER do.
>
>
>
> And rm -rf / (by the way, it wouldn't work if I shouted at your
>
> computer the way you're shouting at me) is actually not the worst
>
> thing I could do. If one of your clients accepts credit cards from his
>
> customers and stores them, I could compromise your client's customers.
>
> They have a measure of trust in the web server; you are betraying that
>
> trust by letting me in.
iI got back root access and i
'rm -y /home/user/public_html/Hello_from_ROSUAV'
so to delete your deface. Thank God you just placed that text file there and did not deface frontpages.
Then i run 'history' to see what exactly you ahve typed but the history log only showed me my own commands.
More information about the Python-list
mailing list