Date: Wed, 29 Oct 1997 10:30:53 -0500 (EST) From: Hetzels@aol.com To: karl@mcs.net Cc: ports@freebsd.org, isp@freebsd.org Subject: Re: Apache FrontPage Module Port Completed Message-ID: <971029103052_1078707231@mrin41.mail.aol.com>
next in thread | raw e-mail | index | archive | help
In a message dated 97-10-28 18:26:35 EST, karl@Mcs.Net (Karl Denninger) writes: > SUID root programs for file transfers should be confined to those which have > many YEARS of experience under their belts - like ftpd. There is absolutely > NO REASON that Microsoft could not support FTP transfers from Frontpage, and > if they did, this entire security fiasco would be moot. > > And yes, I've told Microsoft this -- for almost two years. > > They don't care, and until they do, I'm not risking my machines on their > no-source code. > But they have provided the source code for the FrontPage Module & the fpexe program. Take a look at it. If there is a patch to make it safer let me know and I will gladly include it into the port. Scot
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?971029103052_1078707231>