Tzafrir Cohen wrote:

>On Tue, 8 Jan 2002, Shachar Shemesh wrote:
>
>>I would appretiate it if people who know they installed package X will
>>mail it to this thread, so that we will have a single location where (at
>>least) I know which packages to follow on BugTraq.
>>
>
>bk2site
>
>  A bookmarks system installed by Ira long ago. Is it in use? It probably
>  does not work, as files are not owned by "apache" but by a non-existing
>  user with UID 98
>
>
>consultants, jobs, m
>
>  Local packages (consultants database, jobs database, emails
>  de-obfuscator)
>
m is a cgi that, when addressed, de despams an email address.

For example, try going to the following URL:
http:[EMAIL PROTECTED]

First time I saw it, I suspected that it has a cross site scripting 
vulnerability. I am not sure whether that is the case any more (it uses 
300 errors to redirect the browser to the right address). I think I 
prefer some java script better, but I cannot saw for sure this is not ok.

>
>
>lxr
>
>  Kernel source browser. Installed by mulix
>
>
>yes
>
>  What is this directory? Looks like a left-over
>
>
>exchange
>
>  Shlomi: what is this? Is it doing anything useful? Owner user no longer
>  exists.
>
>
>todo_dir
>
>  Wha is it? The data file is from Mar 9 2000. Owner user no longer
>  exists.
>
>
>qmailadmin
>
>  I don't know more about this.
>
qmailadmin is meant for maintaining the virtual domains. Last time the 
subject was raised, Ira said he installed it. I know how to administrate 
it, but the question is whether anyone is using it.

(go to https://iglu.org.il/cgi-bin/qmailadmin).



----------------------------------------------------------------------------
To unsubscribe, send a message to [EMAIL PROTECTED]
Archives available at http://www.mail-archive.com/[email protected]/

Reply via email to