Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 



Current Newswire:

Extending Nautilus, Scripting Your Way To UI Bliss

Check Your Mysql Server Performance with MySQLTuner

The Growth of the Newest Kubuntu Support Option

Linux Game "System of Tomorrow" Ships in Two Weeks

Anonymous Proxy Using Squid 3 On CentOS 5.x

Install and Configure Cacti Monitoring Tool in Ubuntu 8.10 (Intrepid Ibex) Server

SimplyMEPIS: The Best Desktop Linux You Haven't Tried

Planning Extensions in TYPO3

How the Linux Kernel Manages Virtual Memory

Make Your BIOS Love Security

Sr. Developer, Backend
Professional Technical Resources
US-OR-Eugene

Justtechjobs.com Post A Job | Post A Resume
:PC Week: CGI script opens door
PC Week: CGI script opens door
Oct 4, 1999, 14 :36 UTC (39 Talkback[s]) (14650 reads)

(Other stories by Pankaj Chowdhry)

[ Thanks to anonymous for this link. ]

"The Linux server running PC Week Labs' hackpcweek.com security test site was compromised last week, while the Windows NT server is still up and running as this story goes to press. That does not mean we're declaring Windows NT the security champ; it does mean we're declaring Windows NT easier to secure."

"The hack exploited a weakness in PC Week Labs' CGI script, not in Linux. To secure the Linux box, we applied all of the configuration changes outlined on the Apache Software Foundation's Web site (www.apache.org), along with the Linux How-To recommendations (available at www.linux.com). We did not, however, install the 21 open-source security fixes that are available for Red Hat Linux 6.0-a decision that was criticized by many."

Complete Story

Related Stories:
PC Week: PC Week Labs' site gets hacks-and flak (Sep 28, 1999)
PC Week Secure Linux Site Hacked! (Sep 24, 1999)
PC Week: Hack this: PC Week Labs site begs attacks (Sep 21, 1999)
E-Commerce Times: PC Week to Hackers: 'Make My Day' (Sep 21, 1999)
PRNewswire: PC Week Labs Challenges Hackers To Crack Web Site (Sep 20, 1999)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
I'm not slamming on redhat, but the  ...   Manageabel security updates.   
Justin
Oct 4, 1999, 14:52:50
 
How many hotfixes does Microsft have to  ...   Patches and fixed   
Caitlyn Máire Martin
Oct 4, 1999, 14:53:54
 
PCWeek and parent company Ziff-Davis hav ...   Credibility   
Michael Schwarz
Oct 4, 1999, 14:55:32
 
ZD did not EVEN bother to install the se ...   Let me get this stright..   
Denis Dimick
Oct 4, 1999, 14:57:14
 
So RedHat releases 21 individual updates ...   *** NO SUBJECT ***   
Jonathan
Oct 4, 1999, 14:58:38
 
As many will point out here, Pankaj, it& ...   Chowdhry strikes (out) again   
dizmart
Oct 4, 1999, 14:59:14
 
PC Labs doesn't get it yet. Redhat d ...   Whats the difference here..   
Mike Jones
Oct 4, 1999, 15:03:33
 
YET another zdnet lie.  These guys are r ...   YET ANOTHER ZDNET lie   
Aeonflux
Oct 4, 1999, 15:10:53
 
It is like comparing the sweetness of Le ...   Lemon and Sugarcane   
revengance
Oct 4, 1999, 15:27:39
 
Perhaps they should have said "Easi ...   Easier   
Charles Hixson
Oct 4, 1999, 15:38:34
 
It's rather hard to understand Chowd ...   RedHat fixes - easy to apply!   
Kevin B.
Oct 4, 1999, 15:48:26
 
I think that something very good could c ...   Penguin Approved   
brett
Oct 4, 1999, 15:53:17
 
PC Week has reduced their already low cr ...   Hummmm...   
James Ryan
Oct 4, 1999, 15:57:54
 
Sometimes, I have to wonder if anyone at ...   But that's the problem   
Otis Bricker
Oct 4, 1999, 16:01:21
 
I'm not even gonna give PC Week an e ...   *way* too premature   
Bear Giles
Oct 4, 1999, 16:07:10
 
> Redhat and other large open-source com ...   *** NO SUBJECT ***   
David Walser
Oct 4, 1999, 16:13:02
 
"Anyway, I wonder that ZDNET are full of ...   Re: Lemon and Sugarcane   

Oct 4, 1999, 16:28:32
 
That can be reached from this unscientif ...   The Only Conclusion   
Fran Taylor
Oct 4, 1999, 16:31:09
 
I find it ridiculous that it's harde ...   AutoRPM   
James Williams
Oct 4, 1999, 16:36:28
 
Justin writes:  ''On another not ...   Re: Manageable security updates.   
David Paschall-Zimbel
Oct 4, 1999, 16:56:01
 
The primary weakness that was exploited  ...   The weakness, not in the CGI   
David Wollmann
Oct 4, 1999, 16:56:13
 
After having read RH's announcement  ...   Preempt RH 6.1   
James Lee
Oct 4, 1999, 17:15:42
 
Well, du-uh-uh. Whoda thought they would ...   Duh!   
Bobby D. Bryant
Oct 4, 1999, 17:16:36
 
I have consistently advised the Linux gu ...   Bulldinky!! If your underwear ain't asbestos,   
dinotrac
Oct 4, 1999, 17:26:36
 
For a  PC Week journalist to show such a ...   Regression Testing   
Alan Kitchen
Oct 4, 1999, 18:16:12
 
IBM has been providing piecemeal mainten ...   Enterprise quality maintenance   
bash
Oct 4, 1999, 18:21:07
 
The tone of this article suggests that P ...   Egg on their face...   
bash
Oct 4, 1999, 18:46:52
 
The solution to the "too many security u ...   Time to make a Security-Update-for-dummies webpage   
Julien Rousseau
Oct 4, 1999, 18:53:32
 
It seems to me that Redhat's image a ...   Shouldn't Redhat sue?   
Jim Dabell
Oct 4, 1999, 21:44:49
 
No.No malicious lies were told.The concl ...   Re: Shouldn't Redhat sue?   
dinotrac
Oct 4, 1999, 22:36:50
 
PC Weak says:    To secure the Linux box ...   Lies!   
Lee Malatesta
Oct 5, 1999, 00:14:39
 
Perhaps doing things the Microsoft Way l ...   MS Disease?   
Alan Harris
Oct 5, 1999, 01:33:41
 
Sorry Dave, But IT has always been weak. ...   Re: The weakness, not in the CGI   
AC
Oct 5, 1999, 01:57:36
 
Rather than complain about this, perhaps ...   Different Tack   
AC
Oct 5, 1999, 02:07:24
 
All good points and anything to make sec ...   Re: Different Tack   
dinotrac
Oct 5, 1999, 03:23:52
 
from PC week from the start.....How much ...   Ta..Daaaaaa.....this is expected   
Xunil Ung
Oct 5, 1999, 04:45:56
 
We are talking about a _web server_ here ...   corporate web servers   
geoff lane
Oct 5, 1999, 12:03:54
 
How frigging hard is it to just DOWNLOAD ...   How frigging hard is it to patch?   
Richard Harman
Oct 5, 1999, 13:27:43
 
I was willing to give ZDNet the benefit  ...   Ok! Now they've proven it...   
Mark Turner
Oct 5, 1999, 14:27:29
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................


All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers