Re: Is this secure enough?
| From: | Dean Hall | Date: | Mon, 21 Aug 2000 22:21:12 +0000 |
| Subject: | Re: Is this secure enough? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12824@lists.php.net to get a copy of this message | ||
On Tue, 22 Aug 2000, Jason Brooke wrote:
>
> > As for someone "taking over" the server, I've never heard of
> > this. WU_FTP had such a weakness where a buffer overflow exploit could be
> > used to get a shell as root, but Apache? I've never heard of anyone
> > getting shell access through the webserver. You really don't have anything
> > to worry about there.
>
>
> It's happened many times.
>
> If it happened with the current versions of Apache, it would almost definitely be due to server
> misconfiguration and not through source code security flaws in Apache itself, but it's
> very silly to
> go around saying that a person has nothing to worry about in terms of someone gaining
> unauthorised
> entry to your server.
>
> jason
All right! All right! Enough already! I was wrong!
In fact, I wasn't, because I have never heard of any security flaws in
Apache that would allow this. WU_FTP, for instance, had a flaw that
allowed buffer overflow attacks on PROPERLY configured servers. Apache has
no such vulnerability in properly configured servers, to my knowledge.
Dean.