I don't see in what it would be hard to guess it. Bot admins should know
the difference between a website accessible from the Internet and a
website accessible from a local net: nothing.
More over, I don't think knowing the title of a page is that dangerous.
The only risk is if there is some kind
I don't see in what it would be hard to guess it. Bot admins should know
the difference between a website accessible from the Internet and a
website accessible from a local net: nothing.
More over, I don't think knowing the title of a page is that dangerous.
The only risk is if there is some kind
> There isn't warning about "Unix progstats" command giving out PID,
> username, ...
It doesn't need one. It sounds more likely that it would give out that
kind of thing from its name. That a plugin typically used to print the
of public web pages can be used to poke about the LAN isn't so
obvio
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
09.05.2012 15:17, Ralph Corderoy kirjoitti:
> Mika, I think I explained adequately above. There is no warning in
> the documentation for the plugin that enabling it opens up the LAN
> to interrogation in a way that may not be obvious to the
> administr
Hi bascule, thanks for pointing out the regex but it's hard or
impossible to concoct one that stops LAN access. Blocking numeric IP
addresses isn't sufficient. I argee this plugin is dangerous by default
and yet nowhere in the documentation, or during selection of this
plugin, does it warn the u