Author |
Message |
Janus |
|
Post subject: Re: RE: Re: RE: SOMEONE PLEASE HELP!!
Posted: Jun 22, 2005 - 12:54 PM
|
|

Joined: Apr 12, 2005
Posts: 142
Location: Austin, Texas, USA
Status: Offline
|
|
maarten wrote: | Oh goody a lecture about fucking SCSI yeah i really need some kid explain SCSI to me... You do realise i was using this stuff before you where born right?
And yeah sure you can secure your whole damn box by runnig a Palace server with a limited user account..... sure dude... |
Actually the real security comes from iptables. But yeah... limited user accounts can make a difference too!
What year were you born then? I was born back in Feb of '82! |
|
|
|
|
 |
jon_k |
|
Post subject: Re: RE: Re: RE: SOMEONE PLEASE HELP!!
Posted: Jun 23, 2005 - 01:50 AM
|
|
Joined: Apr 16, 2005
Posts: 45
Status: Offline
|
|
maarten wrote: | Oh goody a lecture about fucking SCSI yeah i really need some kid explain SCSI to me... You do realise i was using this stuff before you where born right?
And yeah sure you can secure your whole damn box by runnig a Palace server with a limited user account..... sure dude... |
Not to lock horns; but yeah.. I do believe that a limited user account is a substantial step to keeping your system secure with the SuExec enabled.
If you run Palace and Apache as root, then all someone has to do is
1) buffer overflow it and gain acces to root
2) ???
2) profit!!!
If you run under a normal old user account, and use SuEXEC to get root only when required
1) buffer overflow
2) you're now under account apache, but unfortunately it's shell account is /bin/false -- you can't do anything
3) ???
4) ???
5) ???
Now, if someone can then cause a buffer overflow under that account, they could in theory get root, however it's a lot more harder.
It's definitely safer.
As for running programs on a limited user account on Windows? You're quite right... might as well just run it as Administrator.
---
As far as SCSI goes, i've never actually owned my own SCSI controller or drive, however I've worked on computers that have. It's an interesting concept and being able to have 8 devices per cable is definitely a novel idea. |
Last edited by jon_k on Jun 23, 2005 - 02:02 AM; edited 1 time in total
|
|
|
|
 |
Janus |
|
Post subject: RE: Re: RE: Re: RE: SOMEONE PLEASE HELP!!
Posted: Jun 23, 2005 - 01:56 AM
|
|

Joined: Apr 12, 2005
Posts: 142
Location: Austin, Texas, USA
Status: Offline
|
|
According to http://en.wikipedia.org/wiki/SCSI
SCSI was officially conceived in 1979. But the 'standard' specs for what we consider SCSI today were conceived in 1986. |
|
|
|
|
 |
|
| |