Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: tlug: WebMin
- To: tlug@example.com
- Subject: Re: tlug: WebMin
- From: Frank Bennett <bennett@example.com>
- Date: Tue, 9 Feb 1999 11:04:26 +0900
- Content-Transfer-Encoding: 7bit
- Content-Type: text/plain; charset=us-ascii
- In-Reply-To: <3.0.6.32.19990209101354.009abb70@example.com>; from Darren Cook on Tue, Feb 09, 1999 at 10:13:54AM +0000
- References: <005401be5349$948ae080$f986e3d2@example.com> <005401be5349$948ae080$f986e3d2@example.com> <19990209100030.A477@example.com> <3.0.6.32.19990209101354.009abb70@example.com>
- Reply-To: tlug@example.com
- Sender: owner-tlug@example.com
On Tue, Feb 09, 1999 at 10:13:54AM +0000, Darren Cook wrote: > >> "Webmin is a web-based interface for system administration for Unix. Using > >> any browser that supports tables and forms, you can setup user accounts, > >> Apache, DNS, file sharing and so on. (www.webmin.com) ..." > > > >This sounds really hazardous; if the server/script is cracked by an > >outsider, you've had it. > > Is it really any worse than allowing telnet on your machine? With telnet if > I can find one users password and the superusers password I can do lots of > damage. Well with a web-based interface I still need to discover these > don't I? The problem, as I understand it, is that the Web server, running as root, invokes the script, also running as root. The Web server designers can beef up security inside their daemon, but they have no control over the external script process. While I don't know the details that well myself, the going wisdom is that SUID scripts are a bad thing, because there are gadzillion ways of breaking them or exploiting them as agents of misbehavior. In this case, breaking the script would yield root access to the system. Game over. Cheers, -- -x80 Frank G Bennett, Jr @@ Faculty of Law, Nagoya Univ () email: bennett@example.com Tel: +81[(0)52]789-2239 () WWW: http://rumple.soas.ac.uk/~bennett/ ------------------------------------------------------------------- Next Technical Meeting: February 13 (Sat), 12:30 place: Temple Univ. ** presentation: XEmacs, by Steven Baur and Martin Buchholz Next Nomikai: March 19 (Fri), 19:30 Tengu TokyoEkiMae 03-3275-3691 ------------------------------------------------------------------- more info: http://tlug.linux.or.jp Sponsor: PHT
- Follow-Ups:
- Re: tlug: WebMin
- From: Darren Cook <darren@example.com>
- References:
- tlug: WebMin
- From: "Renaud ITIER" <Renaud@example.com>
- Re: tlug: WebMin
- From: Frank Bennett <bennett@example.com>
- Re: tlug: WebMin
- From: Darren Cook <darren@example.com>
Home | Main Index | Thread Index
- Prev by Date: Re: tlug: WebMin
- Next by Date: tlug: Unsubscribe
- Prev by thread: Re: tlug: WebMin
- Next by thread: Re: tlug: WebMin
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links