http://qs321.pair.com?node_id=158724


in reply to Careful!
in thread Google - tastic!

I heard somebody claim they wrote a script that gave them root access in under two hours. (They also claimed to be somewhat inexpert with Perl, amusingly enough.)

Hmm, are you talking about me? Nobody claimed that exploit can give root access. Exploit gives shell access under same UID as SOAP::Lite server runs. Unless server runs under root (very bad idea) exploit cannot give root acccess. And I've never claimed that I'm inexpert in Perl :)

And anyway redsquirrel is right: exploit is for SOAP::Lite servers, but not for clients.

--
Ilya Martynov (http://martynov.org/)