From: Anthony A. D. T. <aa...@ta...> - 2001-02-27 18:47:16
|
>Java != Javascript. Nonetheless it kills Netscrape just as dead. >you using IDS for, where people wouldn't already have the ability to >upload arbitrary files by other means? Also, whose security is >compromised by this? Imagine a zip file that contains ../index.cgi, which itself contains #!/bin/sh rm -rf /usr/local/apache or such, in the default case where IDS isn't running under suexec. |