Previous Thread
Next Thread
Print Thread
Rate Thread
#227907 11/18/2002 12:24 AM
Joined: May 1999
Posts: 1,715
Addict
Addict
Joined: May 1999
Posts: 1,715
I used to allow uploading of php-files (haven't for quite a while though) and I just saw a guy who uploaded a couple of different scripts trying to read my config file. Didn't work though, since it's outside the web directory, and it's not possible to run php scripts in the files directory. The guy even tried to make the php files into some binary format to be able to make it run (still didn't work of course).

This happened quite a few months ago, but I haven't seen it until now... The stupid idiot didn't even clean up after himself (like the last guy I found, who at least tried =P), the files are still there.

These damn script-kiddies are everywhere... Following the security instructions from infopop is a very good idea.

Sponsored Links
c0bra #227908 11/18/2002 12:46 AM
Joined: Jun 2002
Posts: 303
Enthusiast
Enthusiast
Joined: Jun 2002
Posts: 303
I only allow .gif, .jpg and .png file uploads. Pardon my ignorance, but can malicious programming be embedded in these file formats?

#227909 11/18/2002 10:14 AM
Joined: Aug 2002
Posts: 1,191
Kahuna
Kahuna
Joined: Aug 2002
Posts: 1,191
Interesting topic. As a matter of fact I was wondering what could happen if you have HTML enabled and one of your users posts something with HTML code embedded in it to retrieve information or to cause damage. Would that work? If yes then surely disabling HTML would solve the problem....

Warm regards

Nikos


Nikos
Hal_dup2 #227910 11/18/2002 10:56 AM
Joined: Nov 2001
Posts: 10,369
I type Like navaho
I type Like navaho
Joined: Nov 2001
Posts: 10,369
Yeah,
Running with HTML on is a bad idea.


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Ruben Rocha
Ruben Rocha
Lutz,FL,USA
Posts: 254
Joined: January 2000
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)