From owner-freebsd-security@FreeBSD.ORG Mon Oct 11 20:52:10 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3181A16A4CE for ; Mon, 11 Oct 2004 20:52:10 +0000 (GMT) Received: from rwcrmhc11.comcast.net (rwcrmhc11.comcast.net [204.127.198.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id DE50D43D1F for ; Mon, 11 Oct 2004 20:52:09 +0000 (GMT) (envelope-from cristjc@comcast.net) Received: from blossom.cjclark.org (c-24-6-187-112.client.comcast.net[24.6.187.112]) by comcast.net (rwcrmhc11) with ESMTP id <2004101120520401300ccd6te>; Mon, 11 Oct 2004 20:52:09 +0000 Received: from blossom.cjclark.org (localhost. [127.0.0.1]) by blossom.cjclark.org (8.12.11/8.12.8) with ESMTP id i9BKq3Vf017025; Mon, 11 Oct 2004 13:52:03 -0700 (PDT) (envelope-from cristjc@comcast.net) Received: (from cjc@localhost) by blossom.cjclark.org (8.12.11/8.12.11/Submit) id i9BKq3VC017024; Mon, 11 Oct 2004 13:52:03 -0700 (PDT) (envelope-from cristjc@comcast.net) X-Authentication-Warning: blossom.cjclark.org: cjc set sender to cristjc@comcast.net using -f Date: Mon, 11 Oct 2004 13:52:03 -0700 From: "Crist J. Clark" To: Abe Usher Message-ID: <20041011205202.GC16819@blossom.cjclark.org> References: <4169DA8C.3000304@sharp-ideas.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4169DA8C.3000304@sharp-ideas.net> User-Agent: Mutt/1.4.2.1i X-URL: http://people.freebsd.org/~cjc/ cc: freebsd-security@freebsd.org Subject: Re: MonkeyShell: using XML-RPC for access to a remote shell X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: "Crist J. Clark" List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 11 Oct 2004 20:52:10 -0000 On Sun, Oct 10, 2004 at 08:57:48PM -0400, Abe Usher wrote: > Security pundits have been warning about the dangers implicit with Web > services for years. http://www.faqs.org/rfcs/rfc3093.html I am not aware of an implementation. It'd be a nice demostration too. -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org