Re: OT: What's up with the starship?



Fredrik Lundh wrote:
Shane Hathaway wrote:

> I don't know if this concern applies to Starship specifically, but it
> seems to apply to thousands of web sites running Python CGIs and
> Python web servers.

so are we seeing thousands of web sites running Python CGIs and web
servers being attacked right now?

No, but it often takes a long time for servers to get patched, so the
window for intruders is going to be open for a while. I'm trying to
understand:

a) how urgent and/or exploitable this is,

b) how I can check whether a given Python installation (running on a
server) has been patched, and

c) whether the security advisory downplays the risk more than it should,
since it appears that many Zope/Plone web servers are vulnerable.

Shane

.



Relevant Pages

  • Re: OT: Whats up with the starship?
    ... so are we seeing thousands of web sites running Python CGIs and web servers being attacked right now? ...
    (comp.lang.python)
  • Re: Websites Finding
    ... They have IPs which are registered to ISP. ... They are using these IP for all servers and running websites from them. ... We have to find out what are the web sites running under each IP/server. ...
    (Pen-Test)