- 论坛徽章:
- 0
|
The title of the first section should be changed to " I hacked a poor website running SCO unix"
Don't know why it's poor?
1. It's running sco openserver/unixware. In north America, it's impossible to use SCO in a military production environment, and SCO might be the lest secure unix OS in the world.
2. It support external ftp connection without limitation. Ftp and telnet service means no security at all.
3. Furthmore, it support ssh connection without public-key verification, only password check. This is not possible for any north America company cares about security, no wonder a military website. If only password check is performed, the connection must be originated from local network at least.
4. The OS contains public known BO vulnerabilities for a hacker who tried "Windows XP data center" , a normal user can be easily escalated to "root".
...
I agree that this artical is creative the author is good at writing, but as a "QA tester", my problem is that I cannot stop finding holes 
[ 本帖最后由 valentine 于 2006-4-26 02:55 编辑 ] |
|