Re: [Nagios-devel] fix request

Support forum for Nagios Core, Nagios Plugins, NCPA, NRPE, NSCA, NDOUtils and more. Engage with the community of users including those using the open source solutions.
Locked
Guest

Re: [Nagios-devel] fix request

Post by Guest »

Hi Ethan,

it is a nasty bug and there are many who still use 3.0.x or even earlier
version
I would suggest the following:

a) a fix for all version atleast 3.x
OR
b) a workaround (announced) e.g. chmod 000 */statuswml.cgi

FYI: our public demo server was attacked and I changed the affected cgi
mode to 000 and owner to root.

Regards,

Badri

Ethan Galstad wrote:
> Roy Sigurd Karlsbakk wrote:
>
>> hi
>>
>> the nagios/cgi-bin/statuswml.cgi?ping=1%3Bcat+%2Fetc%2Fpasswd bug
>> isn't fixed in nagios 3.0. Will that be done, or must I upgrade to 3.1?
>>
>
> Wait another hour or so and 3.2.0 will be out. Otherwise 3.1.x releases
> will fix the problem as well.
>
> - Ethan Galstad
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
> trial. Simplify your report design, integration and deployment - and focus on
> what you do best, core application coding. Discover what's new with
> Crystal Reports now. http://p.sf.net/sfu/bobj-july
> _______________________________________________
> Nagios-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/lis ... gios-devel
>
>






This post was automatically imported from historical nagios-devel mailing list archives
Original poster: [email protected]
Locked