Subject: The mailing list for listmasters using Sympa
List archive
[sympa-users] problem with misterious magic topics on main wwsympa page
- From: Riccardo Veraldi <address@concealed>
- To: address@concealed
- Subject: [sympa-users] problem with misterious magic topics on main wwsympa page
- Date: Thu, 15 Jul 2010 12:38:59 +0200
Hello,
after a nessus Scan my sympa server is showing strange topics strings in the topics home page like
nessus
snoop
SnoopServlet
struts
I found these entries in the sympa database under logs_table.
I deleted them, and apparently everything was back to normality.
Now after a few weeks these strange topics entries are appearing again and disappearing
upon a Reload in the browser of the main sympa page...
I am sure there is no cache in the browser.
I have been searching everywhere and I Could not find any existence of the topics mentioned above
in the DB or elsewhere so I am unable to delete these topcis from the main sympa Home page.
Any hints ?
Where wwsympa is reading those topics, and why prints them ?
Anyway Nessus is able to do a sort of SQL injection and write topics during a nessus SCAN on sympa.
my sympa version is 6.0.1 on Centos 5.5
thank you very much
Riccardo
-
[sympa-users] problem with misterious magic topics on main wwsympa page,
Riccardo Veraldi, 07/15/2010
-
Re: [sympa-users] problem with misterious magic topics on main wwsympa page,
David Verdin, 07/15/2010
- Re: [sympa-users] problem with misterious magic topics on main wwsympa page, Riccardo Veraldi, 07/16/2010
-
Re: [sympa-users] problem with misterious magic topics on main wwsympa page,
David Verdin, 07/15/2010
Archive powered by MHonArc 2.6.19+.