Path: csiph.com!usenet.pasdenom.info!gegeweb.org!de-l.enfer-du-nord.net!feeder2.enfer-du-nord.net!feeds.phibee-telecom.net!newsfeed.xs4all.nl!newsfeed1.news.xs4all.nl!xs4all!post.news.xs4all.nl!not-for-mail Return-Path: X-Original-To: python-list@python.org Delivered-To: python-list@mail.python.org X-Spam-Status: OK 0.076 X-Spam-Evidence: '*H*': 0.85; '*S*': 0.00; 'charset:iso-8859-7': 0.04; 'encoding': 0.05; 'root': 0.05; 'happen,': 0.09; 'subject:script': 0.09; 'sure,': 0.09; 'assume': 0.14; 'fine.': 0.16; 'from:addr:rosuav': 0.16; 'from:name:chris angelico': 0.16; 'subject:Apache': 0.16; 'subject:issue': 0.16; 'subject:run': 0.16; 'subject:python': 0.16; 'wrote:': 0.18; 'bit': 0.19; 'thu,': 0.19; 'certainly': 0.24; 'header:In-Reply-To:1': 0.27; 'point': 0.28; 'am,': 0.29; 'message-id:@mail.gmail.com': 0.30; 'that.': 0.31; "d'aprano": 0.31; 'keys': 0.31; 'steven': 0.31; 'subject:that': 0.31; 'not.': 0.33; 'totally': 0.33; 'trouble': 0.34; 'maybe': 0.34; 'problem': 0.35; "can't": 0.35; 'received:209.85': 0.35; 'received:209.85.220': 0.35; 'point.': 0.35; 'but': 0.35; 'received:google.com': 0.35; 'doing': 0.36; "didn't": 0.36; 'effort': 0.37; 'so,': 0.37; 'received:209': 0.37; 'system,': 0.38; 'feed': 0.38; 'solving': 0.38; 'to:addr:python- list': 0.38; 'issue': 0.38; 'to:addr:python.org': 0.39; 'how': 0.40; 'easy': 0.60; 'most': 0.60; 'gone': 0.61; "you're": 0.61; 'making': 0.63; 'finally': 0.65; 'occur': 0.65; 'contact': 0.67; 'family': 0.73; 'bank': 0.76; 'balance,': 0.84; 'correcting': 0.84; 'everything,': 0.84; 'holidays': 0.84; 'malicious': 0.84; 'strangers': 0.84; 'subject:let': 0.93; 'you...': 0.96; '2013': 0.98 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; bh=tWk6G8/uL+HACgY2UktFgGBJ+rzMfVZdQP1hFIPePZ0=; b=yDyzDnRZDRE+Az5cknnHmQUwRHLsJnYwmLrhkOYl2rtzZQnnoUMj+ZEkQDe5AQCqdG 6vI13jSEBIo3cza9/pLXMqRczP0Y/ydjIDBOxV4AVbW5o2dGCjPe8odHg1c+LZlZfYIf kA9Y9Vh+DQPaZKr5AXTrCPCINuCahLblnEEzVupbrr7UuoPc/yFeZQxl1IvrGHPdiLgW S06KYYf+brBkXsEPEXRKfZSuRbMHDRSGmWEwM9CZOQzx4mOsXLWlNJ/gudDfTK9WQQug QcMmsMz2Pq3IDvzi/0xmHDCqrejDX/SqGLUpNVc5vXHXnFz8WUcoWIOqkpev+sBzDz04 +Ehw== MIME-Version: 1.0 X-Received: by 10.220.109.66 with SMTP id i2mr20799617vcp.51.1370456216391; Wed, 05 Jun 2013 11:16:56 -0700 (PDT) In-Reply-To: References: <20a49aac-3867-481f-96d4-c95a050781ed@googlegroups.com> <592c84d8-2e86-4480-b784-c3ccadc8360d@googlegroups.com> <06fd6c2e-0979-4d61-b75a-6d9df7c1b624@googlegroups.com> <70390d65-5313-46bf-8110-b25f5fc9f76f@googlegroups.com> <8d52505a-7252-419b-8b4f-61e5ee56a78a@googlegroups.com> <2aef9194-ef36-45db-8c77-9510d3f14ebe@googlegroups.com> <8df8a9df-dbb9-4f35-a6a3-b45aa32a848b@googlegroups.com> <1496e27c-7870-48d2-afb0-1bf626e24b5f@googlegroups.com> <83de920f-dea8-49ad-9f6e-e25d3b2d8446@googlegroups.com> <501f3d4e-bbe3-45e8-afce-96cedabe2bef@googlegroups.com> Date: Thu, 6 Jun 2013 04:16:56 +1000 Subject: Re: Apache and suexec issue that wont let me run my python script From: Chris Angelico To: python-list@python.org Content-Type: text/plain; charset=ISO-8859-7 Content-Transfer-Encoding: quoted-printable X-BeenThere: python-list@python.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: General discussion list for the Python programming language List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Newsgroups: comp.lang.python Message-ID: Lines: 28 NNTP-Posting-Host: 2001:888:2000:d::a6 X-Trace: 1370456219 news.xs4all.nl 15945 [2001:888:2000:d::a6]:50067 X-Complaints-To: abuse@xs4all.nl Xref: csiph.com comp.lang.python:47126 On Thu, Jun 6, 2013 at 4:08 AM, =CD=E9=EA=FC=EB=E1=EF=F2 =CA=EF=FD=F1=E1=F2= wrote: > Anyway, i should'n have given root access to you, i was a bit worried doi= ng so, but i was also under stress of also correcting this damn encoding is= sue and i wanted to think you would be the one that finally help solving it= . > > You shouldnt have gone "that far", just to prove a point. > Its not that malicious activity didn't occur to me that migth happen, i j= ust like to think that it wont. Sure, you'd like to think that nothing will ever go wrong. Trouble is, you can't depend on that. Maybe Steven D'Aprano would have solved your problem for you... maybe not. Maybe you would have picked someone who totally smashed your system, reputation, bank balance, and family pet. How would you know? The point of security is not to trust that most people will be fine. The point of security is to be secure. You may not be able to guard against everything, but you can certainly put some effort into not making it easy for an attacker. Treat the root password as a keyring with all of your keys on it, and assume that you're going on holidays overseas. Do you contact strangers to ask them to feed your cat? Or do you talk to a trusted friend? ChrisA