Quote:
This is where I was talking about the type of web applications and the ability to do code verification on web applications. If I can get your web server to perform a buffer overflow, and in turn get that problem to execute commands.
Apache has been installed on a seperate partition meant soley for server programs (See my XP security guide) along as being installed under a seperate user with limited administrative controls. It has very very limited access (the user apache runs under) and this means even more liminted restrictions to what it can call upon. I know there may be a way around that of course, but as you said above... if you make something -that- difficult... :)