7, September 2008

Exploits and Known Issues - webmaster forum

 
Webdigity webmaster forums
This forum shares its ad revenue with its members!
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Exploits and Known Issues
« previous next »
Pages: [1] Print

Author Topic: Exploits and Known Issues  (Read 242 times)
Community Supporter ?
I am a fanatic. So?
*****
Gender: Male
Posts: 541
5184 credits
Members referred : 0


www.demonhale.com


« on: Jun 19, 2008, 06:56:10 AM »

Hey, I have faced something similar of a problem before, and it's a known php script vulnerability. My quick fix before don't seem to work for all situations so Im going to present it here in case someone else has a better solution.

The exploit is a the r57shell.php file installed on the server replacing your index.php file or other files. It is also sometimes named differently but the exploit is still the same. Once it is installed, if someone browses through an infected site. The visitor is automatically is infected by a trojan for windows machine.

So do you guys have any ideas in preventing this known issue once and for all?

http://www.demonhale.com Visit through proxy , Just Visit...
Partners:
http://www.resume-fix.com Visit through proxy , Free Resumes

Last blog : Beijing Olympics Show
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8037
41179 credits
Members referred : 3



« Reply #1 on: Jun 19, 2008, 10:57:34 AM »

The only way for this to happen is by having write permissions in the server. This can be done either by a script that writes and has some bug, or by an XSS vurnerability.

In most cases this type of hacking happens to the whole server. One quick solution is to chown all the files to the root user. This way even if there is the vurnerability there is no way to write the index.php or other file in the server.

In any way you should contact your hosting company as this is probably their problem

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
Community Supporter ?
I am a fanatic. So?
*****
Gender: Male
Posts: 541
5184 credits
Members referred : 0


www.demonhale.com


« Reply #2 on: Jun 25, 2008, 07:53:29 AM »

Would changing the index address other than the index for example via htaccess could at least stop this kind of attempt affect the operation of the site? At least if a server wide attack is made and all files affected are index files, at least your htaccess calls a different named index for your site.

Although it isn't a complete fix to the real problem, at least for the continued operation of a site...

http://www.demonhale.com Visit through proxy , Just Visit...
Partners:
http://www.resume-fix.com Visit through proxy , Free Resumes

Last blog : Beijing Olympics Show
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 8037
41179 credits
Members referred : 3



« Reply #3 on: Jun 25, 2008, 12:00:53 PM »

You don't need to do that. After all this will make your work harder when you are about to install open source software in your sites (where index.php will be always there...)

By changing ownership to root you will be ok

Trial and Error my two best teachers Cool
Join us @ facebook Visit through proxy

Last blog : MIA - Where Nick and Tim
Community Supporter ?
I am a fanatic. So?
*****
Gender: Male
Posts: 541
5184 credits
Members referred : 0


www.demonhale.com


« Reply #4 on: Jun 26, 2008, 11:09:03 AM »

Thanks for the tip Nik, I'' look into that pretty soon, I've been bugged about this since last year, although I had a quick fix, some other hosts do have a different way of handling scripts.

http://www.demonhale.com Visit through proxy , Just Visit...
Partners:
http://www.resume-fix.com Visit through proxy , Free Resumes

Last blog : Beijing Olympics Show
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=7791
Tags : bugs vulnerability server ftp php Bookmark this thread : Digg Del.icio.us Dzone more....

Topic sponsors:
Get a permanent link here for $1.99!


Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Exploits and Known Issues
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Sep 07, 2008, 07:06:26 AM





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 36.301
Total Topics: 7.479
Total Members: 3.904
Tutorials : 56
Resources : 143
Designs : 220
Latest Member: Brandon

20 Guests, 2 Users online :

11 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2008 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.