TUCoPS :: Web :: Adminware, Control Panels :: bigbro~1.txt

Big Brother 1.09 CGI Vulnerability

Date: Mon, 26 Apr 1999 06:49:59 -0400
From: Sean MacGuire <sean@WWW.MACLAWRAN.CA>
Subject: FW: Security Notice: Big Brother 1.09b/c for more info on Big Brother.

Date: Mon, 26 Apr 1999 06:49:59 -0400 (EDT)
>From: Sean MacGuire <>
Subject: Security Notice: Big Brother 1.09b/c

This notice concerns the Big Brother System and Network Monitor.

We noticed you downloaded a version which could be affected by
this problem so we wanted to tell you about it.

If you have any questions or concerns, feel free to contact me
at  Sorry for any inconvenience.

                Big Brother Security Notice

Versions: 1.09b and 1.09c

Module:   CGI History module (web/

Affects:  Anyone who's installed the new history viewer
 as a CGI program.

Summary:  Exploiting the problem could allow the partial
          display of local files provided they are readable
          by your web server, and text-based.

Fix:      Please pick up a new version of the file

Found by: Michael Smith <>  Thanks Michael.

I've also updated the archive to be 1.09d (this is the only
Sean MacGuire, Reality Engineer     
The Big Brother Ministry of Truth
icbm --> 45'31.06N-73'35.19W                    +1 514 982 9688
              "Looking down the barrel of another day"

--------------End of forwarded message-------------------------

