Apache and suexec issue that wont let me run my python script

Νικόλαος Κούρας nikos.gr33k at gmail.com
Wed Jun 5 14:34:30 EDT 2013


Here is the mails you sent to my customers for the other members to see.

-----------------------------------
Greetings.

I apologize for this unsolicited email, but I feel that you have a
right to know about the security of your server. Νικόλαος Κούρας
(Nikos) has been in repeated communication with the members of
python-list with regard to many issues he is having, and he has
happily granted root access to his server to someone he has never met
and has no reason to trust. This compromises your data and your web
site.

Fortunately for you, the person he gave his password is me, and I have
no intention of causing damage. However, if I wanted to, I could do
*anything* to his server. As a simple demonstration, I have placed a
file called Hello_from_Rosuav in the root directory of each of your
web sites, for instance:

http://leonidasgkelos.com/Hello_from_Rosuav
http://parking-byzantio.gr/Hello_from_Rosuav

Your email addresses, too, I obtained from the server. If you are
storing personal details of any of your customers, I could access
those, but on principle I haven't looked.

Please consider carefully who you trust with your hosting. There is no
need to panic right now, as there has been no damage done (beyond the
creation of the file I mentioned above, which you can easily delete).
But be aware that Nikos is not a competent systems administrator, and
I would not trust him with any of my data.

You can find a large number of posts by Nikos on python-list here:
http://news.gmane.org/gmane.comp.python.general
http://mail.python.org/pipermail/python-list/2013-June/thread.html

Feel free to contact me for further details. I apologize that I cannot
communicate in Greek; I hope that this will not be a problem.

I advise that you look to alternative web hosting.
-----------------------------------

Thanks for screwing me up entirely and made me look what you made me look for all i did was to trust you.



More information about the Python-list mailing list