Date: Tue, 31 Aug 1999 20:30:22 -0700 From: Bill Swingle <unfurl@dub.net> To: Laurence Berland <stuyman@confusion.net> Cc: Liam Slusser <liam@tiora.net>, Kevin Lynn <klynn@santacruz.org>, Peter Kok <cckok00@stlinux.ouhk.edu.hk>, security@FreeBSD.ORG Subject: Re: hotmail Message-ID: <19990831203022.A8558@dub.net> In-Reply-To: <37CC9BC7.45CE961E@confusion.net>; from Laurence Berland on Tue, Aug 31, 1999 at 11:21:43PM -0400 References: <Pine.GSO.4.05.9908312011040.675-100000@kinetic.tiora.net> <37CC9BC7.45CE961E@confusion.net>
next in thread | previous in thread | raw e-mail | index | archive | help
This is correct. Hotmail has ~1800 FreeBSD boxen as webservers and their database stuff is run on Sun boxen running Solaris. -Bill On Tue, Aug 31, 1999 at 11:21:43PM -0400, Laurence Berland wrote: > Last I heard the frontend that served up the pages was FreeBSD, and the > mail backend for incoming and outgoing mail was Solaris. BTW the > exploit was just telling the cgi script you wanted the post-login page > or some page just after login that you wanted that page, and it just > assumed that you were already authenticated (which you weren't). > Nothing to do with freebsd, just a bad cgi program. > > Liam Slusser wrote: > > > > I thought hotmail was using Sun hardware running Solaris? Anybody > > know? > > > > liam -- -=| --- B i l l S w i n g l e --- http://www.dub.net/ -=| unfurl@dub.net - unfurl@freebsd.org - bill@cdrom.com -=| Different all twisty a of in maze are you, passages little To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?19990831203022.A8558>