Security Basics mailing list archives

Re: question regarding exploits


From: Chris Largret <largret () gmail com>
Date: Tue, 08 Nov 2005 12:35:01 -0800

On Mon, 2005-11-07 at 06:14 -0800, Juan B wrote:

I have a ftp server Serv-U. I want to check it for
volunrabilities  I stared using Whoppix live linux

Whoppix has been renamed to Whax. You might download a new version :-)

 I ran a search for this version under securityfocus.com
database and I found many exploits,few of tham are
with an extantion of .shtml like this one indexdate.shtml 

what should I do with those? 

.shtml is an extension used on web servers that support server-side
includes. As far as you (as a user) are concerned, they behave just like
regular .html files.

maybe copy and paste theyre contant and than compile ?

I'm don't follow, but you may take a look at the tool Nessus. It is
moving toward the world of closed-source, but it does provide links to
pages that describe how to close vulnerabilities that it finds.

--
Chris Largret <http://daga.dyndns.org>


Current thread: