[Fwd: Informix Web Driver]
Posted in 2001
Final comments, as many of you and some on the bugtraq list suggested, this was a default installation. We all know that installing any application which has tools that are suid root is asking for trouble (actually, so is installing an o/s period). as you can see, this was a default install... the words people, as soon as you connect to a network you are opening your machine up to things worse than hackers.... users. brett isno wrote: > > Hello! > As John Wright mentioned "everything quoted is examples of a default install where > no configuration has been done." It is like what I said,this vulnerability is DEFAULT > installation,and the symlink vulnerability is the same default configuration. > > I installed Informix Webdriver v3.0 on my SunOS 5.6 box,the web server is > APACHE 1.3.9.And I do not any configuration,let it run with all default configuration. > When I type URL I found the vulnerability. > > Webdriver make /tmp/.log with permissions -rw-rw-rw- when it was under Debug > running ,but it is the default configuration.Because I only install the webdriver, > I do NOT any configuration works. > > Good Luck!!! > > isno(isno@etang.com) -- ----------------------------------------------------------------- Brett's 11th law of UNIX administration... Users think that Y2K was a non-event... well... They havn't got our overtime bills yet :) ----------------------------------------------------------------- Brett Geer - UNIX Admin/Analyst/Programmer - Intratex Holdings. Tel. +27 31 717 4000 Direct. +27 31 717 4146 Fax. +27 31 717 4001 ----------------------------------------------------------------- The little voices are talking to me again, telling me to reach for a keyboard and type rm -rf /* last week they had me rm -rf `echo $MANPATH | sed 's/:/ /g'` now I fear I have no answers -----------------------------------------------------------------