Re: [Mailman-Users] message about probes

2009-04-30 Thread Donna Dierker
Sapiro Cc: Gruver, Sandi; 'mailman-users@python.org' Subject: Re: [Mailman-Users] message about probes Mark Sapiro writes: > Gruver, Sandi wrote: > > 2 possible successful probes > > /mailman/private/sqlhelp///includes/session.php?baseDir=../../ ../../../../../..

Re: [Mailman-Users] message about probes

2009-04-30 Thread Stephen J. Turnbull
Steff Watkins writes: > > Aha, I see where I went wrong ... /mailman is an Apache ScriptAlias > (or equivalent), isn't it. (I prefer a cgi-bin ScriptAlias so > > it's immediately obvious what the URL is supposed to resolve to.) > They're both "obvious" where they point to if > you look thro

Re: [Mailman-Users] message about probes

2009-04-29 Thread Steff Watkins
@python.org' > Subject: Re: [Mailman-Users] message about probes > > Mark Sapiro writes: > > Gruver, Sandi wrote: > > > > 2 possible successful probes > > > > /mailman/private/sqlhelp///includes/session.php?baseDir=../../ ../../../../../../etc/p

Re: [Mailman-Users] message about probes

2009-04-29 Thread Mark Sapiro
Stephen J. Turnbull wrote: >Mark Sapiro writes: > > Gruver, Sandi wrote: > > > > 2 possible successful probes > > > /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd > > > HTTP Response 200 > > [...] > > if you look in Mailman's error log, you'll see

Re: [Mailman-Users] message about probes

2009-04-29 Thread Stephen J. Turnbull
Mark Sapiro writes: > Gruver, Sandi wrote: > > 2 possible successful probes > > /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd > > HTTP Response 200 > > I saw the same thing in my Logwatch the other day. These messages are > reported in the

Re: [Mailman-Users] message about probes

2009-04-29 Thread Mark Sapiro
Gruver, Sandi wrote: >>From the mailman server's Logwatch program: > >A total of 1 sites probed the server > 62.1.205.86 > > 2 possible successful probes > /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd > HTTP Response 200 > /mailman/admin///includ

[Mailman-Users] message about probes

2009-04-29 Thread Stephen J. Turnbull
Gruver, Sandi writes: > 2 possible successful probes > > /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd > HTTP Response 200 > > /mailman/admin///includes/session.php?baseDir=../../../../../../../../etc/passwd > HTTP Response 200 > >

[Mailman-Users] message about probes

2009-04-28 Thread Gruver, Sandi
>From the mailman server's Logwatch program: A total of 1 sites probed the server 62.1.205.86 2 possible successful probes /mailman/private/sqlhelp///includes/session.php?baseDir=../../../../../../../../etc/passwd HTTP Response 200 /mailman/admin///includes/session.php?baseDir=../../.