Beefy Boxes and Bandwidth Generously Provided by pair Networks
Clear questions and runnable code
get the best and fastest answer

Re^2: Security, root and CGI?

by Anonymous Monk
on Jan 29, 2009 at 19:02 UTC ( #739992=note: print w/replies, xml ) Need Help??

in reply to Re: Security, root and CGI?
in thread Security, root and CGI?

My advice: If you want security then stay away from Webmin.

Or atleast, that's my advice from looking at it a couple of years ago... it's implementation that is... I gave up trying to explain the security risk to the author... exploits that could be easily verfied (and fixed) were only met with a response: 'fixed in xyz' (testing xyz revealed it was not fix - so much for testing)

Also: webmin runs everything as root. Only thing it takes is one little exploit in one of the module and you have root access. (And unless the code really changed in the past years then I'm sure there are many exploits in it)

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://739992]
LanX for they know not what they do ...

How do I use this? | Other CB clients
Other Users?
Others making s'mores by the fire in the courtyard of the Monastery: (11)
As of 2017-10-20 11:15 GMT
Find Nodes?
    Voting Booth?
    My fridge is mostly full of:

    Results (261 votes). Check out past polls.