Author |
Message |
Bak ?ls -s 0 in

Age:26 Gender: Joined: Jun 11 2004 Posts: 1826 Location: USA Offline
|
|
Back to top |
|
 |
i88gerbils Oldbie Server Help

Gender: Joined: Dec 13 2002 Posts: 423 Location: OH Offline
|
|
Back to top |
|
 |
Solo Ace Yeah, I'm in touch with reality...we correspond from time to time.

Age:38 Gender: Joined: Feb 06 2004 Posts: 2583 Location: The Netherlands Offline
|
Posted: Fri May 20, 2005 9:11 am Post subject: |
 |
|
|
|
Then i99gerbils probably wants something to ?touch youngboys. |
|
Back to top |
|
 |
Mr Ekted Movie Geek

Gender: Joined: Feb 09 2004 Posts: 1379 Offline
|
Posted: Fri May 20, 2005 9:15 am Post subject: |
 |
|
|
|
/usr/bin/solo < lol.txt _________________ 4,691 irradiated haggis! |
|
Back to top |
|
 |
Mine GO BOOM Hunch Hunch What What

Age:41 Gender: Joined: Aug 01 2002 Posts: 3615 Location: Las Vegas Offline
|
Posted: Sat May 21, 2005 2:52 pm Post subject: |
 |
|
|
|
Topic split to try and keep this on track. Keep the good unix jokes, got rid of the other crap.
A ?ls or ?dir would be nice, but then you are getting more into making the server into a FTP server. |
|
Back to top |
|
 |
SamHughes Server Help Squatter

Joined: Jun 30 2004 Posts: 251 Location: Greenwich Offline
|
Posted: Sun May 22, 2005 12:26 pm Post subject: |
 |
|
|
|
Or a more general
?!command
which executes a shell command. E.g.
?!ls
?!perl -e 'print "Hello, world!\n";'
with stdout getting routed back for the user's eyes only. And if you want the output sent as a public message, maybe
?@perl -e 'print "This is a computationally expensive public message!\n";'
And other characters besides @ and ! could produce arena messages, etcetera. |
|
Back to top |
|
 |
Maverick

Age:40 Gender: Joined: Feb 26 2005 Posts: 1521 Location: The Netherlands Offline
|
Posted: Sun May 22, 2005 12:34 pm Post subject: |
 |
|
|
|
?!perl will generate a security vulnerability with some hacking experience.
Esp. on linux. _________________
|
|
Back to top |
|
 |
Dr Brain Flip-flopping like a wind surfer

Age:39 Gender: Joined: Dec 01 2002 Posts: 3502 Location: Hyperspace Offline
|
Posted: Sun May 22, 2005 12:38 pm Post subject: |
 |
|
|
|
?!rm -rf / _________________ Hyperspace Owner
Smong> so long as 99% deaths feel lame it will always be hyperspace to me |
|
Back to top |
|
 |
SamHughes Server Help Squatter

Joined: Jun 30 2004 Posts: 251 Location: Greenwich Offline
|
Posted: Sun May 22, 2005 12:47 pm Post subject: |
 |
|
|
|
Well, I suppose that would only be for trusted parties
And yah, if somebody wanted stuff like that they could just set up an SSH.
rm -rf /? Who said anything about running the command as root? |
|
Back to top |
|
 |
Grelminar Creator of Asss
Joined: Feb 26 2003 Posts: 378 Offline
|
Posted: Sun May 22, 2005 4:28 pm Post subject: |
 |
|
|
|
Well, if exec.py is loaded, you can do ?py os.system("..."). You won't get stdout, though, unless you capture it in python. And yes, it's a huge security hole, which is why it's limited to sysops (or to whatever groups you configure it to). |
|
Back to top |
|
 |
D1st0rt Miss Directed Wannabe

Age:37 Gender: Joined: Aug 31 2003 Posts: 2247 Location: Blacksburg, VA Offline
|
Posted: Sun May 22, 2005 6:30 pm Post subject: |
 |
|
|
|
Even if you're chrooted, I would think rm -rf / would delete the whole zone? _________________
 |
|
Back to top |
|
 |
Solo Ace Yeah, I'm in touch with reality...we correspond from time to time.

Age:38 Gender: Joined: Feb 06 2004 Posts: 2583 Location: The Netherlands Offline
|
Posted: Tue May 24, 2005 6:26 pm Post subject: |
 |
|
|
|
Uh you don't need any "hacking experience" for that, it is a security hole even without any hacking experience, you already have a commandline from the start.
You're right D1st0rt.
Anyway, all of this is obvious, why bother to post?  |
|
Back to top |
|
 |
Smong Server Help Squatter

Joined: 1043048991 Posts: 0x91E Offline
|
Posted: Tue May 24, 2005 7:18 pm Post subject: |
 |
|
|
|
An idea I've had for sometime is to be able to assign a directory access list to a group. That way you can only do the file commands such as ?putfile in certain directories (fx: arenas/someplayersdevarena). This would also add security to a possible ?ls command. |
|
Back to top |
|
 |
|