Re: Site Traffic Reporting



Juan T. Llibre shared this with us in
microsoft.public.dotnet.framework.aspnet:

> I am very skittish about it, since I don't have awstats installed,
> but see quite a few requests for /cgi-bin/awstats.pl in my weblogs.

A few months ago there was a security flaw in awstats, a buffer
overflow vulnerability if I'm correct. If there were exploits, they
were created *after* awstats was patched.
How often do you see that with IIS vulnerabilities?

> Perl has been demonstrated to be a security risk in many previous
> versions and I don't want to be the booby who proves that the
> version of Perl which awstats uses is a security risk, too.

Replace every instance of the word Perl with IIS in that sentence, and
it remains a valid statement. Is that a reason for not using IIS? No, I
should think. For Perl you use exactly the same precautions as for any
other technology.


Anyway, see this page: http://aspn.activestate.com/ASPN/NET
Perl can be used as any other .NET language.

--
Amedee Van Gasse
.



Relevant Pages

  • Re: Site Traffic Reporting
    ... > Do you know of an unfixed IIS vulnerability? ... awstats is a good product, its worth taking a look at - but Juan is correct ... > Juan T. Llibre ... >>> version of Perl which awstats uses is a security risk, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Site Traffic Reporting
    ... They seem to occur more often with Perl than with other languages. ... Do you know of an unfixed IIS vulnerability? ... level with Perl, which also introduces additional, unneeded, security concerns. ... >> I am very skittish about it, since I don't have awstats installed, ...
    (microsoft.public.dotnet.framework.aspnet)
  • =?ISO-8859-15?Q?Anf=E4ngerfrage?= XWhois.pm
    ... Auf dem vserver ist ein Verzeichnis ... Awstats macht aber keine weiteren whois-infos. ... Wie bring ich das zum Laufen, ohne mich intensiv mit Perl zu befassen? ... Kann ich XWhois auf der Konsole laufen lassen ...
    (de.comp.lang.perl.misc)
  • Re: analyzing IIS6 log files using a c# or VB tool?
    ... > I posted a question a while ago about and AWSTats was suggested. ... but the top two use perl and java. ... It has a COM+ interface that you could probably use ...
    (microsoft.public.inetserver.iis)
  • Re: IIS + AWSTATS
    ... I installed ActivePerl and AWStats without ... > So this means something with permissions... ... or user IUSR_SERVERNAME (default used user by IIS on NT). ... With IIS, if a default cgi-bin directory was created during IIS install, ...
    (microsoft.public.inetserver.iis.security)

Loading