[lug] cgi shell

jd lug at taproot.bz
Mon Feb 3 16:23:02 MST 2003


Hello,
 Today at slashdot there is a write-up about
a cgi shell.
http://slashdot.org/article.pl?sid=03/02/03/1531246&mode=thread&tid=162&tid=156

so i downloaded it and tried it...pretty scary, it allowed me
to get to / and go where ever I wanted. Is there a way to
allow users to have a cgi-bin but stop this sort of behavior?

Thanks,
jd





More information about the LUG mailing list