Re: [PHP] Securing your sites against Script Kiddies

2008-04-22 Thread paragasu
> http://ambiguous.dnsalias.net/ what a nice collection you have. i also have some of this files on my server. i don't know how the files end up on my web page directory. That time i am using a shared server with 300+ website hosted on the same host. i do not have ssh or telnet access (ftp and

[PHP] Securing your sites against Script Kiddies

2008-04-22 Thread Wolf
For all of you with an upload/access page to your site that is world-viewable I have made available copies of scripts that kiddies have tried to use to take over my own server. As my upload page has yet to be broken nor my site taken over, I wanted to share them with everyone as a way to learn

Re: [PHP] Securing your Sites

2007-12-17 Thread Wolf
--- >> From: Wolf [mailto:[EMAIL PROTECTED] >> Sent: 17 December 2007 16:00 >> To: [EMAIL PROTECTED] >> Cc: php-general@lists.php.net >> Subject: Re: [PHP] Securing your Sites >> >> Funny, they should all be PHPS, source only and my last check only did >&g

Re: [PHP] Securing your Sites

2007-12-17 Thread Daniel Brown
On Dec 17, 2007 11:27 AM, Jeremy Mcentire <[EMAIL PROTECTED]> wrote: > Wait, I'm confused. Did PHP send a virus to your computer without > action on your part? That'd be scary. If you downloaded something, > was the checksum not published for you to verify your download prior > to unpacking it?

Re: [PHP] Securing your Sites

2007-12-17 Thread Wolf
; -Original Message- >> From: Wolf [mailto:[EMAIL PROTECTED] >> Sent: 17 December 2007 16:00 >> To: [EMAIL PROTECTED] >> Cc: php-general@lists.php.net >> Subject: Re: [PHP] Securing your Sites >> >> Funny, they should all be PHPS, source on

Re: [PHP] Securing your Sites

2007-12-17 Thread Jeremy Mcentire
Wait, I'm confused. Did PHP send a virus to your computer without action on your part? That'd be scary. If you downloaded something, was the checksum not published for you to verify your download prior to unpacking it? That's always a warning worthy of apprehension. What was the "PHP-B

RE: [PHP] Securing your Sites

2007-12-17 Thread Dan Parry
> -Original Message- > From: Wolf [mailto:[EMAIL PROTECTED] > Sent: 17 December 2007 16:00 > To: [EMAIL PROTECTED] > Cc: php-general@lists.php.net > Subject: Re: [PHP] Securing your Sites > > Funny, they should all be PHPS, source only and my last check only

RE: [PHP] Securing your Sites

2007-12-17 Thread Dan Parry
> -Original Message- > From: Wolf [mailto:[EMAIL PROTECTED] > Sent: 17 December 2007 16:00 > To: [EMAIL PROTECTED] > Cc: php-general@lists.php.net > Subject: Re: [PHP] Securing your Sites > > Funny, they should all be PHPS, source only and my last check only

Re: [PHP] Securing your Sites

2007-12-17 Thread Wolf
Funny, they should all be PHPS, source only and my last check only did them on the source viewing. None of them are executable in that folder. You got it from elsewhere. [EMAIL PROTECTED] wrote: > I want to personally thank you for 6 hours of work to remove the > PHP-Back-door Trojan, that down

RE: [PHP] Securing your Sites

2007-12-17 Thread admin
I want to personally thank you for 6 hours of work to remove the PHP-Back-door Trojan, that download from your site to my PC while viewing that POS you call a help line. -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

[PHP] Securing your Sites

2007-12-16 Thread Wolf
For all of you with an upload/access page to your site that is world-viewable I have made available copies of scripts that kiddies have tried to use to take over my own server. As my upload page has yet to be broken nor my site taken over, I wanted to share them with everyone as a way to learn how