Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
Old 07-04-2006, 09:13 PM Php Shells
Junior Talker

Posts: 3
Trades: 0
Hey, I figured you guys would know a lil bit about this so here goes.
Im trying to start this free blogs service, I dont have no auto sign up script, just installatron on the control panel, its like fantastico. Anyway at first I was gonna give everyone an ftp account cause i had safe mode on, exec off, shell exec off, and lo and behold the **** php shells they make now can still work on that. Cant even make a mod security rule for it.
Here is one by some russian hack crew, they are all like this now, maybe someone can tell me how to stop this yet still let legit scripts run.
http://evolution-security.com/files/...ll_build17.zip
felosi is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 07-05-2006, 09:09 AM Re: Php Shells
ibbo's Avatar
Super Spam Talker

Posts: 880
Location: Leeds UK
Trades: 0
A rather interesting file name with extremely worrysome content.

If they can get these scripts up to your server and run them then your virtually opening a door for them build a profile of not just you but your server too.

If in doubt keep em out.
And if they are dumping scripts like that on your server you realy need to keep them out.

I am supprised your ISP has not been intouch as of yet.

Ibbo
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Linux user #349545 :
(GNU/Linux)iD8DBQBAzWjX+MZAIjBWXGURAmflAKCntuBbuKCWenpm XoA7LNydllVQOwCf
ibbo is offline
Reply With Quote
View Public Profile Visit ibbo's homepage!
 
Old 07-05-2006, 09:31 PM Re: Php Shells
Junior Talker

Posts: 3
Trades: 0
Quote:
Originally Posted by ibbo
A rather interesting file name with extremely worrysome content.

If they can get these scripts up to your server and run them then your virtually opening a door for them build a profile of not just you but your server too.

If in doubt keep em out.
And if they are dumping scripts like that on your server you realy need to keep them out.

I am supprised your ISP has not been intouch as of yet.

Ibbo
No no one has uploaded anything like that yet but when you have free or even regular webhosting services it is always good to take precautions. You cannot always depend on your customers to run everything in the most secure fashion so I try to make it where if they are compromised it will not spill over into the rest of the server.
I am just trying to figure out what makes these new style php shells tick so I can disable or configure whatever to prevent it. Used to disabling exec and shell exec was enough but if you experment with that then you will see its something way different.
I think any host with common sense should know whats going on out in the wild and the precautions to take, it doesnt matter if your just hosting church sites or what.
I dont understand what you mean about my isp, Maybe you have misunderstood something but I have my own server and been trying my best to be prepared against all known threats, Actually I guess if I wanted to I could upload something to the server and delete the entire thing lol, It doesnt matter to them. They are real cool and security minded people as well but I do not bother them with small things I am working on.

So no one knows what particular php functions that shell uses and what to disable to stop it?
felosi is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Php Shells
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.18022 seconds with 12 queries