Full Disclosure mailing list archives

Re: Re: Remote root exploit for mod_gzip (with debug_mode)


From: Ben Nelson <lists () venom600 org>
Date: Thu, 20 Nov 2003 14:01:26 -0700

I s'pose it's only a 'root' exploit if you're running your webserver as root.

--Ben

martin f krafft wrote:
also sprach Alexander Antipov <pk95 () yandex ru> [2003.11.20.2028 +0100]:

/      uid=99(nobody) gid=99(nobody) groups=99(nobody)


where is the root exploit?


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: