[404] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: CIAC Advisory F-11 Report: Unix NCSA httpd Vulnerability

daemon@ATHENA.MIT.EDU (Chuck McManis)
Thu Feb 16 18:23:16 1995

Date: Thu, 16 Feb 1995 11:57:46 -0800
From: cmcmanis@scndprsn.Eng.Sun.COM (Chuck McManis)
To: www-security@ns2.rutgers.edu
Reply-To: www-security@ns2.rutgers.edu
Errors-To: owner-www-security@ns2.rutgers.edu

Also if you do patch the source to do the bounds check, do yourself
a favor and log any system that trys to exploit this bug. Such information
is extremely useful in tracking down penetration attempts on your system
from systems that are already penetrated (possibly without the knowledge
of the sysadmin). 

--Chuck McManis
Sun Microsystems

home help back first fref pref prev next nref lref last post