[sage-support] Potential Security Hole -- sh (shell) in Notebook

2010-04-01 Thread TianWei
The sh option in the sage notebook allows anyone to access the command-line shell on the sage server. This grants users access to any directory on the server, including configuration settings, etc. Even on the Try Sage Online link on the main page (www.sagenb.org) lets users do this. This is a

Re: [sage-support] Potential Security Hole -- sh (shell) in Notebook

2010-04-01 Thread Robert Bradshaw
On Apr 1, 2010, at 6:04 PM, TianWei wrote: The sh option in the sage notebook allows anyone to access the command-line shell on the sage server. This grants users access to any directory on the server, including configuration settings, etc. Even on the Try Sage Online link on the main page