Full Disclosure mailing list archives
Fwd: solution to wu-ftpd + tar program execution
From: "smith jerome" <securebox () hotmail com>
Date: Mon, 08 Sep 2003 11:59:34 +0300
This has been known for a long time: http://www.security-express.com/archives/bugtraq/1999-q4/0405.html There is an easy solution to this which don't cut functionality: in ftpconversions place " -- " before "%s" in every line which has tar (probably on all lines is a good idea). " -- " terminates the arguments passed to tar, so programs can't be injected. linux distributions were notified about the solution, debian released an advisory at: http://www.debian.org/security/2003/dsa-377 georgi _________________________________________________________________Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn.com/?page=features/featuredemail
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Fwd: solution to wu-ftpd + tar program execution smith jerome (Sep 08)