28, May 2012

Free Links no wait nasty Evil Bug - webmaster forum

 
Webdigity webmaster forums
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Free Links no wait nasty Evil Bug
« previous next »
Pages: [1] Print
Instabuck - The easy way to sell digital products online

Author Topic: Free Links no wait nasty Evil Bug  (Read 2536 times)
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2175
5052 credits
Members referred : 2


Venture Skills - New Media & IT group


« on: Apr 27, 2007, 11:39:38 pm »

So depending on your point of view a great way to get back links or an Evil XSS attack focused around phpinfo()
http://www.davidnaylor.co.uk/archives/2007/04/27/would-anyone-like-some-free-backlinks/

A programmer at David Naylor Blog has full details, don't you just love it when not only you find a bug but its one spammers can use!

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO alternatively for Social media optimisation take a look at the Venture Skills Blog

Last blog : Its all in the mp3s
Global Moderator
Internet Junkie
*****
Gender: Male
Posts: 1807
9006 credits
Members referred : 6



« Reply #1 on: Apr 27, 2007, 11:55:16 pm »

Thats a nasty bug, which I'm sure will be used by a lot of people.


Last blog : Are You Stumbling Yet?
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #2 on: Apr 28, 2007, 12:12:12 am »

great, and it works also with version 4.3.11

I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« Reply #3 on: Apr 28, 2007, 01:01:25 pm »

Hmmm. Today I made a script that takes full advantage of this Smiley

My only prob is how to get those links indexed.

BTW do you think it would be wise to sell that script or I should just keep it for me and my friends?

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Tim Nash
Global Moderator
Community Supporter ?
Internet Junkie
*****
Posts: 2175
5052 credits
Members referred : 2


Venture Skills - New Media & IT group


« Reply #4 on: Apr 28, 2007, 02:28:05 pm »

I wouldn't sell it might damage your reputation how about making a bit of a tutorial out of it, and include the how to secure such problems Wink

Would you like to be an SEO, let me help with, The Tim Nash introduction to SEO alternatively for Social media optimisation take a look at the Venture Skills Blog

Last blog : Its all in the mp3s
Bill Gates is my home boy
*****
Gender: Female
Posts: 710
4449 credits
Members referred : 2



« Reply #5 on: Apr 29, 2007, 12:08:09 am »

Hmm, I wish I understood what was happening here.

Forgive the stupid question - but is this based on the version of php my host is using?

If you make a tutorial on how to protect against this, please let me know - then maybe I could hope to understand what this is all about.

www.yourmessageconsultant.com, providing online content and printed marketing materials.
www.helpforwebbeginners.com, Tutorials and how to's for new  webmasters.
www.CraftyTips.com, a unique Arts & Crafts Directory
www.nocans.com - Pet Food Recipe Site
www.petsiteguides.com - A New Pet Directory

Last blog : Spring Cleaning at Crafty Tips
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6691
34714 credits
Members referred : 374


It's time to use PHP5!


« Reply #6 on: Apr 29, 2007, 07:54:44 am »

Hmm, I wish I understood what was happening here.

Forgive the stupid question - but is this based on the version of php my host is using?

If you make a tutorial on how to protect against this, please let me know - then maybe I could hope to understand what this is all about.

how to protect? don't publish a phpinfo file Smiley

I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5799
46391 credits
Members referred : 3



« Reply #7 on: Apr 29, 2007, 03:26:24 pm »

Tim, you are right it would be wrong to publish that.

YMC, having a phpinfo() page on your server may be a real problem. This specific "bug" is not really a problem for the host owner.

But phpinfo can - some times - provide critical information to a hacker Smiley

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=6477
Tags : xss php Bookmark this thread : Digg Del.icio.us Dzone more....

Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Free Links no wait nasty Evil Bug
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 28, 2012, 07:31:40 am





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 62.849
Total Topics: 11.032
Total Members: 21.456
Tutorials : 58
Resources : 929
Designs : 395
Latest Member: ketnoimang

159 Guests, 3 Users online :

20 users online today:




Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2012 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.