On Wed, 14 Jun 2006, Stephen Gran wrote:
>
> If it is a root compromise, of course, you're screwed anyway, but a
> simple push over of a php script running as a non-privileged httpd user
> may not kill you in this case.

Except that Marc explicitly wants his httpd user to be able to send email.
I wonder if he lets his users install CGIs.

Tony.
-- 
<[EMAIL PROTECTED]>   <[EMAIL PROTECTED]>   http://dotat.at/   ${sg{\N${sg{\
N\}{([^N]*)(.)(.)(.*)}{\$1\$3\$2\$1\$3\n\$2\$3\$4\$3\n\$3\$2\$4}}\
\N}{([^N]*)(.)(.)(.*)}{\$1\$3\$2\$1\$3\n\$2\$3\$4\$3\n\$3\$2\$4}}

-- 
## List details at http://www.exim.org/mailman/listinfo/exim-users 
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://www.exim.org/eximwiki/

Reply via email to