Path: csiph.com!newsfeed.hal-mli.net!feeder3.hal-mli.net!newsfeed.hal-mli.net!feeder1.hal-mli.net!newsfeed.xs4all.nl!newsfeed3.news.xs4all.nl!xs4all!newsgate.cistron.nl!newsgate.news.xs4all.nl!post.news.xs4all.nl!not-for-mail Return-Path: X-Original-To: python-list@python.org Delivered-To: python-list@mail.python.org X-Spam-Status: OK 0.016 X-Spam-Evidence: '*H*': 0.97; '*S*': 0.00; 'charset:iso-8859-7': 0.04; 'root': 0.05; '"if': 0.09; 'permissions': 0.09; 'subject:extra': 0.09; 'subject:string': 0.09; '(file': 0.16; 'exist.': 0.16; 'from:addr:rosuav': 0.16; 'from:name:chris angelico': 0.16; 'least)': 0.16; 'login?': 0.16; 'subject:when': 0.16; 'subject:python': 0.16; 'do,': 0.16; 'fix': 0.17; 'wrote:': 0.18; 'do.': 0.18; 'thu,': 0.19; 'url:view': 0.20; 'appears': 0.22; '(in': 0.22; 'shell': 0.22; "aren't": 0.24; 'header:In-Reply- To:1': 0.27; 'appear': 0.29; 'chris': 0.29; 'am,': 0.29; 'subject:list': 0.30; 'message-id:@mail.gmail.com': 0.30; "i'm": 0.30; 'changed.': 0.31; 'up:': 0.31; 'yes.': 0.31; 'file': 0.32; 'another': 0.32; 'cases': 0.33; 'maybe': 0.34; 'subject:from': 0.34; 'problem': 0.35; 'something': 0.35; 'but': 0.35; 'received:google.com': 0.35; 'google': 0.35; 'accessing': 0.36; 'appearance': 0.36; 'i.e.': 0.36; 'done': 0.36; 'seconds': 0.37; 'wrong': 0.37; 'easily': 0.37; 'problems': 0.38; 'others.': 0.38; 'to:addr:python-list': 0.38; 'anything': 0.39; 'does': 0.39; 'to:addr:python.org': 0.39; 'called': 0.40; 'how': 0.40; 'skip:u 10': 0.60; 'tell': 0.60; 'simply': 0.61; 'offer': 0.62; 'protection': 0.63; 'kind': 0.63; 'total': 0.65; 'different': 0.65; 'yes': 0.68; 'home': 0.69; 'jul': 0.74; 'account.': 0.80; 'subject:space': 0.84; '2013': 0.98 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; bh=mJrWzJ5DbaVbR6WJ++F8vdxbFhYAsVmb3yRHMuEWiO8=; b=RWAs1kdABeWqnCNl4MMUXbCtxoEcvHEl4PZTN3YUs+Qv3ELDRKOk8TPQkSpisbyI6B wnrIiYOL3w+dbyNF4DQgvrf7J7lUIR2ofwLh36lBuKMvWhZNpMAr6BVu55aLSKP7ETn5 Tgs7jQ2AFKIlu6KjviIj7Sx2uZESDxTEaZjHYS/pScGspnQoc9qARKdsg/psnXm2Opw7 fx8PjXcfOnWjvqH7AfAfDg4lb17yNEK8IdMPKfNmGQsE+ohB5MMny4GOmZeGQ8q145hk /Pd9vinmh5MuHkfC78zPgIW7eCyvRhPTIQNnKd2a4nrCVnYiDdwoF7jFVIHXTv0w3CdV xdeQ== MIME-Version: 1.0 X-Received: by 10.52.120.77 with SMTP id la13mr508196vdb.23.1372872214475; Wed, 03 Jul 2013 10:23:34 -0700 (PDT) In-Reply-To: References: <51D1D484.5070309@rece.vub.ac.be> <51D27FB9.7040406@rece.vub.ac.be> <51D2C113.6070105@rece.vub.ac.be> <1264cfb9-f451-40e3-9d59-0619547c8138@googlegroups.com> <51D3ED24.9030202@rece.vub.ac.be> Date: Thu, 4 Jul 2013 03:23:34 +1000 Subject: Re: python adds an extra half space when reading from a string or list From: Chris Angelico To: python-list@python.org Content-Type: text/plain; charset=ISO-8859-7 Content-Transfer-Encoding: quoted-printable X-BeenThere: python-list@python.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: General discussion list for the Python programming language List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Newsgroups: comp.lang.python Message-ID: Lines: 51 NNTP-Posting-Host: 2001:888:2000:d::a6 X-Trace: 1372872222 news.xs4all.nl 15995 [2001:888:2000:d::a6]:38618 X-Complaints-To: abuse@xs4all.nl Xref: csiph.com comp.lang.python:49765 On Thu, Jul 4, 2013 at 3:07 AM, =CD=DF=EA=EF=F2 wrote: > =D3=F4=E9=F2 3/7/2013 7:53 =EC=EC, =EF/=E7 Chris Angelico =DD=E3=F1=E1=F8= =E5: >> What are the file permissions (file modes) on all your home >> directories? Do you know what they mean? > > > root@nikos [~]# ls -al /home > total 88 > drwx--x--x 22 root root 4096 Jul 3 20:03 ./ > drwxr-xr-x 22 root root 4096 Jun 12 01:21 ../ > drwx--x--x 14 akis akis 4096 Apr 5 22:21 akis/ > same with others just +x for group and others. > > Does that mean you can easily i.e. 'cd /home/akis/' accessing their home > directories? Yes. > Shall i 'chmod -x /home/dirs' ? Only if you know what it will do. Your solutions to problems always seem to be "If I do this, will the problem be fixed?" without demonstrating any understanding of what will be changed. Maybe you do know and aren't showing it, but I suspect that (in many cases at least) you simply do not understand what you are doing. >> I'm happy to take you up on that offer if you need another lesson in >> not giving out shell access. And don't forget, privilege escalation >> attacks do exist. > > > Yes they do, but cPanel offers some protection against these kind of meth= ods > called "CPHulk" so it wont be easy! Neat. Now I know how to lock you out of your own account. Five seconds with Google brought this up: http://docs.cpanel.net/twiki/bin/view/11_30/WHMDocs/CPHulk Can you, by reading that page, tell me what I would have to do to stop you from accessing your login? Also, CPHulk does not appear to have _any_ protection against privilege escalation. It's a completely different thing. So once again, it appears - maybe that appearance is wrong - that you have done something that "ought to fix security" without knowing anything about what it actually does. ChrisA