That site, the script just get the input, then perform a whois command: whois $input (no check performed on $input) then print out ANYTHING it got (even worse!)
say $input = | ls -l
A nice/harmless one!
Anyway, by having this exploit, the site opens a hole for people on the shared
server (I actually did a listing of all sites on that server)
Too bad I didn't know much of Linux commands to do some interesting experiments!
Check out: neworder.box.sk if you're interested in security stuff.
<Edited by 123finder.com on 12-03-2000 at 03:35 PM>