|
From: SourceForge.net <no...@so...> - 2004-07-17 15:48:35
|
Feature Requests item #992899, was opened at 2004-07-17 10:48 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=992899&group_id=34096 Category: Packages Group: None Status: Open Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: add trapdoor2 Initial Comment: http://oss.linbit.com/trapdoor2/ trapdoor2 (td2) allows remote users to execute local commands by sending 'magic cookies'. this can e.g. be used to alter local firewalling rules so people can connect to local services after sending the magick cookie. td2 is implemented as high-secure https server. the daemon processes are running in a chroot jail with multiple rlimits set. even if td2 can be exploited (e.g. using a hypothetical security hole in the SSL implementation), it is very unlikely that the attacker can execute any commands on the machine and/or can cause any damage. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=992899&group_id=34096 |