hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Programming Discussion : IMPORTANT For SERVER OWNERS.
Reply

Programming Discussion Discussions related to web programming languages and other related issues. Topics may include configuration, optimization, practical usage and database connectivity.
Forum Jump

IMPORTANT For SERVER OWNERS.

Reply Post New Thread In Programming Discussion Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 09-07-2002, 12:58 AM
host911 host911 is offline
WHT Addict
 
Join Date: Nov 2001
Location: Toronto, Canada
Posts: 111
Exclamation

IMPORTANT For SERVER OWNERS.


Hello,

I don't know if any of you saw this script before, it's called PHPSHELL, even if you didn't allow telnet or SSH on you server they can view your root directories. I think all server owners should block or delete this script from their servers.

the URL is: http://www.gimpster.com/php/phpshell/index.php

Take care,

Reply With Quote


Sponsored Links
  #2  
Old 09-07-2002, 01:14 AM
Nadav Nadav is offline
Junior Guru
 
Join Date: May 2002
Posts: 219
Eeek. Scary.

Reply With Quote
  #3  
Old 09-07-2002, 02:08 AM
MultiVol MultiVol is offline
WHT Addict
 
Join Date: Aug 2002
Posts: 136
Scary

__________________
Western Man

Reply With Quote
Sponsored Links
  #4  
Old 09-07-2002, 05:43 AM
Rich2k Rich2k is offline
Web Hosting Master
 
Join Date: May 2002
Location: UK
Posts: 2,994
Surely the functions required to run such a script are blocked by safe_mode ?

Reply With Quote
  #5  
Old 09-07-2002, 05:44 AM
MultiVol MultiVol is offline
WHT Addict
 
Join Date: Aug 2002
Posts: 136
Ahh the safe mode, hmm...

__________________
Western Man

Reply With Quote
  #6  
Old 09-07-2002, 12:57 PM
DavidU DavidU is offline
Web Hosting Guru
 
Join Date: Jun 2001
Location: San Diego, CA
Posts: 283
what a dumb program

What a stupid program...

heh.

It runs as the webuser so I think the potential damage is pretty low but you never know...could hit up other webusers's files and molest them.

-davidu

__________________
EveryDNS.NET :: FreeDNS and more.

Reply With Quote
  #7  
Old 09-08-2002, 02:30 AM
dreamrae.com dreamrae.com is offline
Web Hosting Master
 
Join Date: Aug 2002
Location: Baltimore, Maryland
Posts: 580
ahhh!!!

Reply With Quote
  #8  
Old 09-08-2002, 04:04 AM
DD-SNC DD-SNC is offline
Web Hosting Master
 
Join Date: Sep 2002
Location: Oklahoma
Posts: 825
Thumbs down PHPSHELL BLOWS GOATS!

This script is very very gay.

__________________
Devon Dunham (Owner, Sharpnet/DDoS Host)
Advanced DDoS Mitigation and Server Management Solutions

Protecting your online infrastructure.

Est. 1998.


Reply With Quote
  #9  
Old 09-08-2002, 06:31 AM
microsol microsol is offline
Web Hosting Master
 
Join Date: Jul 2001
Location: /dev/null
Posts: 1,219
This script is very old. You should be save if you run php in safe mode.

Reply With Quote
  #10  
Old 09-08-2002, 07:17 AM
roby2k roby2k is offline
Junior Guru
 
Join Date: Apr 2002
Location: Wirral/Cheshire/Meresyside
Posts: 203
just to let u know users are very limited on what they can see and use. they have no way of altering things they maybe able to view somethings but not all if i remember right they can not see most things it will just redirect to the folder the file is in everytime they try to do something.

__________________
http://www.gocre8.co.uk - Liverpool Web Design
http://www.outallnite.co.uk - Liverpool Clubbing

Reply With Quote
  #11  
Old 09-08-2002, 12:51 PM
DavidU DavidU is offline
Web Hosting Guru
 
Join Date: Jun 2001
Location: San Diego, CA
Posts: 283
Re: PHPSHELL BLOWS GOATS!

Quote:
Originally posted by DD-SNC
This script is very very gay.
How can a php script be gay?

Has AI technology progressed that much?

-davidu

__________________
EveryDNS.NET :: FreeDNS and more.

Reply With Quote
  #12  
Old 09-08-2002, 12:58 PM
LinuXpert LinuXpert is offline
Web Hosting Master
 
Join Date: Apr 2002
Posts: 565
Quote:
Originally posted by roby2k
just to let u know users are very limited on what they can see and use. they have no way of altering things they maybe able to view somethings but not all if i remember right they can not see most things it will just redirect to the folder the file is in everytime they try to do something.
yes, that's right. They can't even delete their own files. This script is not new, actually there are many scripts like this written in Perl.

__________________
AceWebHosting.Com
Cheap Web Hosting - Multiple Domain Hosting - Reseller Hosting - Virtual Private Server


Reply With Quote
  #13  
Old 09-08-2002, 03:03 PM
apokalyptik apokalyptik is offline
Newbie
 
Join Date: Aug 2002
Posts: 19
OI!

Truth: I didnt even bother looking at the script

Truth: I probably know what it does

Description: runs commands typed into a web browser

Truth: these commands are then run as the httpd daemon username, on unix this is probably 'nobody'. In this case you can _ONLY_ execute command with o+x, and _ONLY_ read files with o+r, and _ONLY_ modify files with o+w (duh?)

Truth: this script idea is about 10 years old

Truth: if you're really paranoid about this script then do one of a couple things: 1) look into user mode linux 2) chroot 3) stop web hosting, because worrying about this is like worrying about whether or not your win2k box is secure - its just dumb.

sorry, thats my opinion

__________________
irc.apokalyptik.com http://www.apokalyptik.com http://www.apokalyptik.com/forum/

Reply With Quote
  #14  
Old 09-08-2002, 03:57 PM
bonahost bonahost is offline
Newbie
 
Join Date: Aug 2002
Posts: 5
Quote:
Originally posted by NetworksData

yes, that's right. They can't even delete their own files. This script is not new, actually there are many scripts like this written in Perl.
As far php run as nobody in your server, I can make your server down using this script.

Reply With Quote
  #15  
Old 09-08-2002, 04:02 PM
DavidU DavidU is offline
Web Hosting Guru
 
Join Date: Jun 2001
Location: San Diego, CA
Posts: 283
Quote:
Originally posted by bonahost


As far php run as nobody in your server, I can make your server down using this script.
But the real question is: "Can you write a complete sentence?"

And by "down" do you mean cracked, DoS'd, or what?

A DoS does not show any sort of skill whatsoever and is pretty much reserved for fools and morons.

-davidu

__________________
EveryDNS.NET :: FreeDNS and more.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host OrcsWeb Offers Support for Windows Server 2012 Web Hosting News 2012-08-24 11:08:35
Jakarta Web Hosting Introduces MSSQL Server 2012 Hosting Services Web Hosting News 2012-04-23 11:18:07
Web Host Nexcess Launches Enterprise Managed Server Clusters for WordPress Web Hosting News 2012-01-30 11:28:59
Security Firm ArtSec Launches Website and Server Migration Service Web Hosting News 2011-12-09 18:43:03
Certificate Authority Comodo Releases Free E-commerce Site Scanning Tool Web Hosting News 2011-06-23 17:27:14


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?