[lug] cgi shell

peter at hutnick.com peter at hutnick.com
Mon Feb 3 16:10:52 MST 2003


> Hello,
>  Today at slashdot there is a write-up about
> a cgi shell.
> http://slashdot.org/article.pl?sid=03/02/03/1531246&mode=thread&tid=162&tid=156
>
> so i downloaded it and tried it...pretty scary, it allowed me
> to get to / and go where ever I wanted. Is there a way to
> allow users to have a cgi-bin but stop this sort of behavior?

Chroot the webserver?

-Peter





More information about the LUG mailing list