Re: Webmin Vulnerability Leads to Remote Compromise (RPC CGI)

From: Muhammad Faisal Rauf Danka (mfrdat_private)
Date: Fri Aug 30 2002 - 08:09:17 PDT

  • Next message: Daniel Ahlberg: "GLSA: ethereal"

    The problem has been fixed several versions before.
    Current version is 0.990
    However I am using version 0.980 of webmin.
    And the default installation value for rpc in defaultacl file is 2.
    
    [root@linux /]# grep "rpc" /home/admin/webmin-0.980/defaultacl 
    rpc=2
    [root@linux /]# 
    
    Regards
    --------
    Muhammad Faisal Rauf Danka
    
    Head of GemSEC / Chief Technology Officer
    Gem Internet Services (Pvt) Ltd.
    web: www.gem.net.pk
    Key Id: 0x784B0202
    Key Fingerprint: 6F8C EDCF 6C6E 06A5 48D7  6A20 C592 484B 
    784B 0202
    
    _____________________________________________________________
    ---------------------------
    [ATTITUDEX.COM]
    http://www.attitudex.com/
    ---------------------------
    
    _____________________________________________________________
    Promote your group and strengthen ties to your members with emailat_private by Everyone.net  http://www.everyone.net/?btn=tag
    



    This archive was generated by hypermail 2b30 : Fri Aug 30 2002 - 08:25:41 PDT