Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Possible Apache 2.0.47 / PHP 4.3.2 / Gentoo Exposure Problem
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
chrisc
n00b
n00b


Joined: 18 Sep 2003
Posts: 3

PostPosted: Thu Sep 18, 2003 12:54 pm    Post subject: Possible Apache 2.0.47 / PHP 4.3.2 / Gentoo Exposure Problem Reply with quote

Hi, I'm not a Gentoo user but was using netcat to view a server running Gentoo today. I connected to the server running the above configuration and type ``GET /'' (I know it's not standard compliant, but it works ;)). The server proceeded to kick out a LOT of noise. Inside this noise appears to be (I don't know the distro, hence ``possible...'') start-up scripts and details pertaining to dependencies (possibly the Gentoo port system?). Whatever it is it appears to be a Bourne Shell script. I have advised the admin of that system, and he hasn't got back to me yet, so I'm sorry if this is just a problem with his configuration. I also do not have another server running a similar configuration to find out if this problem is just Gentoo-based, or is a problem with one of the two packages stated (although it looks like PHP has tried to format the data, the top half of this data appears to be phpinfo();). I doubt it's exploitable, as the user has no way to use any of this data directly (although indirectly it may help)...but, if this data were edited, and the changes would want to be kept private this is a problem.

As I said, sorry if this is waste of time.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum