[19194] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Fwd: Re: phpnuke, security problem...

daemon@ATHENA.MIT.EDU (sam mulvey)
Tue Feb 13 18:46:43 2001

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.LNX.4.32.0102131314290.6155-100000@vac.vis.nu>
Date:         Tue, 13 Feb 2001 13:17:19 -0700
Reply-To: sam mulvey <sam@VIS.NU>
From: sam mulvey <sam@VIS.NU>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <20010212210410.F55386@dataloss.nl>

On Mon, 12 Feb 2001, Peter van Dijk wrote:

> The author obviously doesn't care about security.

He's not, and he makes it perfectly clear in the installation
instructions:

"3) In order to use the File Manager, please be sure to chmod 666 ALL
files and 777 ALL directories.

4) Also, to activate Headlines you "need" to chmod 777 the "cache"
directory, otherwise headlines won't work."

It's a nice piece of software, otherwise.  Just have to be careful about
which part to use..

--
#!/usr/bin/perl
# Sam Mulvey -- vis.nu Networks
# No Translation Phenomenon Outside!
$_ = "http://sam.vis.nu"; s-[\w]*://([\w]*)\.-$1\@-; print;

home help back first fref pref prev next nref lref last post