Possible successful probe?
David Guntner <davidg-1boXBf7wef/[email protected]> Mon, 12 Dec 2011 07:29:00 -0800
| Newsgroups | gmane.linux.mandrake.expert |
|---|---|
| Organization | What a concept! :-) |
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig0F66278F048CB7F8A28C3B4B
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Still running my semi-crippled 2011 install - haven't had a chance to do
anything about that, yet.... :-)
Anyway, this morning's security run reported the following:
> A total of 3 possible successful probes were detected (the following U=
RLs
> contain strings that match one or more of a listing of strings that
> indicate a possible exploit):
> =20
> /?file=3D../../../../../../proc/self/environ%00 HTTP Response 200=20
> /?mod=3D../../../../../../proc/self/environ%00 HTTP Response 200=20
> /?page=3D../../../../../../proc/self/environ%00 HTTP Response 200=20
That's all it says, so I'm not sure what the reset of the URL was.
Question is, is the above anything I need to worry about? Is there
going to be any information that they could get from the above that
might allow them to compromise my machine?
--Dave
--------------enig0F66278F048CB7F8A28C3B4B
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAk7mHcAACgkQvC3peSYrMN75sgCfcx1QZpNCwPKfXW6sr1tOpIZz
fPAAnip1VUgBWwx1qfZTfij2JWukkipP
=jpx+
-----END PGP SIGNATURE-----
--------------enig0F66278F048CB7F8A28C3B4B--