16, March 2010

Free Links no wait nasty Evil Bug - webmaster forum

 
Webdigity webmaster forums
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Free Links no wait nasty Evil Bug
« previous next »
Pages: [1] Print

Author Topic: Free Links no wait nasty Evil Bug  (Read 1682 times)
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2175
5052 credits
Members referred : 2


Venture Skills - New Media & IT group


« on: Apr 28, 2007, 12:39:38 am »

So depending on your point of view a great way to get back links or an Evil XSS attack focused around phpinfo()
http://www.davidnaylor.co.uk/archives/2007/04/27/would-anyone-like-some-free-backlinks/

A programmer at David Naylor Blog has full details, don't you just love it when not only you find a bug but its one spammers can use!

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO alternatively for Social media optimisation take a look at the Venture Skills Blog

Last blog : Its all in the mp3s
Global Moderator
Internet Junkie
*****
Gender: Male
Posts: 1807
9006 credits
Members referred : 6



« Reply #1 on: Apr 28, 2007, 12:55:16 am »

Thats a nasty bug, which I'm sure will be used by a lot of people.


Last blog : Are You Stumbling Yet?
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6690
34708 credits
Members referred : 374


It's time to use PHP5!


« Reply #2 on: Apr 28, 2007, 01:12:12 am »

great, and it works also with version 4.3.11


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5659
45587 credits
Members referred : 3



« Reply #3 on: Apr 28, 2007, 02:01:25 pm »

Hmmm. Today I made a script that takes full advantage of this Smiley

My only prob is how to get those links indexed.

BTW do you think it would be wise to sell that script or I should just keep it for me and my friends?

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2175
5052 credits
Members referred : 2


Venture Skills - New Media & IT group


« Reply #4 on: Apr 28, 2007, 03:28:05 pm »

I wouldn't sell it might damage your reputation how about making a bit of a tutorial out of it, and include the how to secure such problems Wink

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO alternatively for Social media optimisation take a look at the Venture Skills Blog

Last blog : Its all in the mp3s
Bill Gates is my home boy
*****
Gender: Female
Posts: 710
4449 credits
Members referred : 2



« Reply #5 on: Apr 29, 2007, 01:08:09 am »

Hmm, I wish I understood what was happening here.

Forgive the stupid question - but is this based on the version of php my host is using?

If you make a tutorial on how to protect against this, please let me know - then maybe I could hope to understand what this is all about.

www.yourmessageconsultant.com, providing online content and printed marketing materials.
www.helpforwebbeginners.com, Tutorials and how to's for new  webmasters.
www.CraftyTips.com, a unique Arts & Crafts Directory
www.nocans.com - Pet Food Recipe Site
www.petsiteguides.com - A New Pet Directory

Last blog : Spring Cleaning at Crafty Tips
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6690
34708 credits
Members referred : 374


It's time to use PHP5!


« Reply #6 on: Apr 29, 2007, 08:54:44 am »

Hmm, I wish I understood what was happening here.

Forgive the stupid question - but is this based on the version of php my host is using?

If you make a tutorial on how to protect against this, please let me know - then maybe I could hope to understand what this is all about.

how to protect? don't publish a phpinfo file Smiley


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5659
45587 credits
Members referred : 3



« Reply #7 on: Apr 29, 2007, 04:26:24 pm »

Tim, you are right it would be wrong to publish that.

YMC, having a phpinfo() page on your server may be a real problem. This specific "bug" is not really a problem for the host owner.

But phpinfo can - some times - provide critical information to a hacker Smiley

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=6477
Tags : xss php Bookmark this thread : Digg Del.icio.us Dzone more....

Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Free Links no wait nasty Evil Bug
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Mar 16, 2010, 12:40:03 pm





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!





Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2010 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.