fix request

Badri Pillai badri at diglinks.com
Thu Aug 13 10:01:21 CEST 2009


Hi Ethan,

it is a nasty bug and there are many who still use 3.0.x or even earlier
version
I would suggest the following:

a)  a fix for all version atleast 3.x
       OR
b) a workaround (announced) e.g. chmod 000 */statuswml.cgi

FYI: our public demo server was attacked and I changed the affected cgi
mode to 000 and owner to root.

Regards,

Badri

Ethan Galstad wrote:
> Roy Sigurd Karlsbakk wrote:
>   
>> hi
>>
>> the nagios/cgi-bin/statuswml.cgi?ping=1%3Bcat+%2Fetc%2Fpasswd bug  
>> isn't fixed in nagios 3.0. Will that be done, or must I upgrade to 3.1?
>>     
>
> Wait another hour or so and 3.2.0 will be out.  Otherwise 3.1.x releases
> will fix the problem as well.
>
> - Ethan Galstad
>
> ------------------------------------------------------------------------------
> Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
> trial. Simplify your report design, integration and deployment - and focus on 
> what you do best, core application coding. Discover what's new with 
> Crystal Reports now.  http://p.sf.net/sfu/bobj-july
> _______________________________________________
> Nagios-devel mailing list
> Nagios-devel at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/nagios-devel
>
>   


------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july




More information about the Developers mailing list