[33199] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Re[2]: Hijacking Apache 2 via mod_perl

daemon@ATHENA.MIT.EDU (Steve G)
Thu Jan 22 16:40:06 2004

Message-ID: <20040122175110.26816.qmail@web9604.mail.yahoo.com>
Date: Thu, 22 Jan 2004 09:51:10 -0800 (PST)
From: Steve G <linux_4ever@yahoo.com>
To: 3APA3A <3APA3A@SECURITY.NNOV.RU>, Ben Laurie <ben@algroup.co.uk>
Cc: Steve Grubb <linux_4ever@yahoo.com>, bugtraq@securityfocus.com,
        httpd security <security@httpd.apache.org>
In-Reply-To: <60705914.20040122203700@SECURITY.NNOV.RU>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii

>At least, it's  possible  to  store  descriptors  table  and
>implement  check for descriptor  in  every  perl  file/socket
>function  inside mod_perl (and mod_php  and mod_something) and 
>only allow access to std descriptors and to  descriptors open
>inside same script. The choice is between speed and security.

Right. To me, that sounds ideal. In these days of 3 GHz machines,
I don't mind a little extra checking if it makes things more
secure.

-Steve Grubb

__________________________________
Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!
http://webhosting.yahoo.com/ps/sb/

home help back first fref pref prev next nref lref last post