[11149] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Redhat 6.0 cachemgr.cgi lameness

daemon@ATHENA.MIT.EDU (Henrik Nordstrom)
Tue Jul 27 18:26:46 1999

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id:  <379DE794.2183A5B0@hem.passagen.se>
Date:         Tue, 27 Jul 1999 19:08:36 +0200
Reply-To: hno@HEM.PASSAGEN.SE
From: Henrik Nordstrom <hno@HEM.PASSAGEN.SE>
X-To:         Kerb <kerb@FNUSA.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

Kerb wrote:

> others?).  Also, it could have POSSIBLY been Squid, which I installed as a
> proxy cache.  Just some thoughts....

As I said earlier cachemgr.cgi is part of Squid and the RedHat package
manager has apparently selected /home/http/cgi-bin as a appropriate
place to install cachemgr.cgi even thought is its a administrative
interface which should be protected.

cachemgr.cgi has nothing to do with Apache.

Source to the program is available in the Squid sources as
src/cachemgr.c. Squid sources is available from http://squid.nlanr.net/
(or on your RedHat sources CD)

--
Henrik Nordstrom
Squid developer

home help back first fref pref prev next nref lref last post