Web Hosting Talk







View Full Version : IMPORTANT For SERVER OWNERS.


host911
09-07-2002, 12:58 AM
Hello,

I don't know if any of you saw this script before, it's called PHPSHELL, even if you didn't allow telnet or SSH on you server they can view your root directories.:mad: I think all server owners should block or delete this script from their servers.

the URL is: http://www.gimpster.com/php/phpshell/index.php

Take care,

Nadav
09-07-2002, 01:14 AM
Eeek. Scary.

MultiVol
09-07-2002, 02:08 AM
:eek: :eek: Scary

Rich2k
09-07-2002, 05:43 AM
Surely the functions required to run such a script are blocked by safe_mode ?

MultiVol
09-07-2002, 05:44 AM
Ahh the safe mode, hmm...

DavidU
09-07-2002, 12:57 PM
What a stupid program...

heh.

It runs as the webuser so I think the potential damage is pretty low but you never know...could hit up other webusers's files and molest them.

-davidu

dreamrae.com
09-08-2002, 02:30 AM
ahhh!!!

DD-SNC
09-08-2002, 04:04 AM
This script is very very gay.

microsol
09-08-2002, 06:31 AM
This script is very old. You should be save if you run php in safe mode.

roby2k
09-08-2002, 07:17 AM
just to let u know users are very limited on what they can see and use. they have no way of altering things they maybe able to view somethings but not all if i remember right they can not see most things it will just redirect to the folder the file is in everytime they try to do something.

DavidU
09-08-2002, 12:51 PM
Originally posted by DD-SNC
This script is very very gay.

How can a php script be gay?

Has AI technology progressed that much?

-davidu

LinuXpert
09-08-2002, 12:58 PM
Originally posted by roby2k
just to let u know users are very limited on what they can see and use. they have no way of altering things they maybe able to view somethings but not all if i remember right they can not see most things it will just redirect to the folder the file is in everytime they try to do something.
yes, that's right. They can't even delete their own files. This script is not new, actually there are many scripts like this written in Perl.

apokalyptik
09-08-2002, 03:03 PM
Truth: I didnt even bother looking at the script

Truth: I probably know what it does

Description: runs commands typed into a web browser

Truth: these commands are then run as the httpd daemon username, on unix this is probably 'nobody'. In this case you can _ONLY_ execute command with o+x, and _ONLY_ read files with o+r, and _ONLY_ modify files with o+w (duh?)

Truth: this script idea is about 10 years old

Truth: if you're really paranoid about this script then do one of a couple things: 1) look into user mode linux 2) chroot 3) stop web hosting, because worrying about this is like worrying about whether or not your win2k box is secure - its just dumb.

sorry, thats my opinion :) :D ;) :stickout :cool: :rolleyes:

bonahost
09-08-2002, 03:57 PM
Originally posted by NetworksData

yes, that's right. They can't even delete their own files. This script is not new, actually there are many scripts like this written in Perl.

As far php run as nobody in your server, I can make your server down using this script.

DavidU
09-08-2002, 04:02 PM
Originally posted by bonahost


As far php run as nobody in your server, I can make your server down using this script.

But the real question is: "Can you write a complete sentence?"

And by "down" do you mean cracked, DoS'd, or what?

A DoS does not show any sort of skill whatsoever and is pretty much reserved for fools and morons.

-davidu

iamdave
09-08-2002, 07:10 PM
Originally posted by roby2k
just to let u know users are very limited on what they can see and use. they have no way of altering things they maybe able to view somethings but not all if i remember right they can not see most things it will just redirect to the folder the file is in everytime they try to do something. Pretty much what the case was with plesk, I instlled it, and I was only able to navigate within the current directory..

ntwaddel
09-08-2002, 09:53 PM
that script shouldent be able to do much if you have open_basedir on and safe mode on.

iamdave
09-08-2002, 09:56 PM
Originally posted by ntwaddel
that script shouldent be able to do much if you have open_basedir on and safe mode on. Yep!

LinuXpert
09-08-2002, 09:59 PM
Originally posted by ntwaddel
that script shouldent be able to do much if you have open_basedir on and safe mode on.
How about Perl scripts?

mind21_98
09-08-2002, 11:41 PM
Originally posted by DavidU
What a stupid program...

heh.

It runs as the webuser so I think the potential damage is pretty low but you never know...could hit up other webusers's files and molest them.

-davidu

Some people might not agree, but those kinds of programs have their uses. When I was at Hypermart (the free business hosting site), I used a CGI program I wrote to compile some stuff that I needed. This doesn't mean you shouldn't monitor for this though; it just means you should pay attention to what people are doing exactly with their scripts.

benoire
09-09-2002, 09:54 AM
Why isn't there a demo of the script on their site? :D

Heh, nowt to worry about though, you can't do anything you couldn't do another way.

YUPAPA
09-19-2002, 01:27 AM
Yep, Perl can do that... but if you change permission for the root directory with proper permission, they can't view it.

Alan - Vox
09-19-2002, 05:54 PM
But the real question is: "Can you write a complete sentence?"

Perhaps haps you should of stopped and thought for a second before posting that. Perhaps english is his second language.

dreamrae.com
09-20-2002, 09:02 PM
once again ahh!!!

YUPAPA
09-20-2002, 11:16 PM
Originally posted by SplashHost.com

Perhaps haps you should of stopped and thought for a second before posting that. Perhaps english is his second language.

who are you talking to?

JustinH
09-21-2002, 01:46 AM
Probably the person he quoted... But it could be that Alan is just mumbling :).