Re: [CentOS] Apache mod_perl cross site scripting vulnerability

2015-08-12 Thread Ellen Shull
On Wed, Aug 12, 2015 at 3:39 AM, Proxy One wrote: > Is there way to use curl for testing? I'm getting new line because of > the single quote inside string and escaping it with back slash gives me > bash: syntax error near unexpected token `<' You can use curl's -K option which lets you stick argu

Re: [CentOS] Apache mod_perl cross site scripting vulnerability

2015-08-11 Thread Ellen Shull
On Tue, Aug 11, 2015 at 4:46 AM, Proxy One wrote: > I haven't used but Trustwave still finds me > vulnerable. > [...] > Response: HTTP/1.1 404 Not Found You clearly aren't serving perl-status; that's a red herring here. [...] > Body: contains '">alert('xss')' That's your problem; they're flag

Re: [CentOS] Software RAID1 with CentOS-6.2

2012-02-28 Thread Ellen Shull
On Tue, Feb 28, 2012 at 5:27 PM, Kahlil Hodgson wrote: > Now I start to get I/O errors on printed on the console.  Run 'mdadm -D > /dev/md1' and see the array is degraded and /dev/sdb2 has been marked as > faulty. I had a problem like this once. In a heterogeneous array of 80 GB PATA drives (it