Skip to content

BE CAREFULL RUNNING THIS ON PUBLIC SERVERS! #12

Description

@realriccio

The python script "host.py" allows for arbitrary file upload!

Although there is some checking it can be easily bypassed to upload a file anywhere on your system!

And since it has to be run as root for the port 443 to be usable A REMOTE ACTOR CAN REPLACE ANY FILE OF YOUR SERVER AS ROOT, LEADING TO FULL SYSTEM TAKEOVER!

I won't go into any more details but it's easily, easily exploitable. Please remove the upload functionality from the script.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions