RE: Is this as bad as it seems?

From: Enquiries (Enquiries@globalart4u.com)
Date: 07/31/02


From: "Enquiries" <Enquiries@globalart4u.com>
To: <security-basics@securityfocus.com>
Date: Tue, 30 Jul 2002 23:10:15 +0100


(if php or perl are allowed (or any active content), it's as good as a shell
acount for that purpose)

Could you please explain this to me in laymans language? Does this mean
that php can be hacked easily?



Relevant Pages

  • Re: PHP [win32] & CLI Testers needed.
    ... written, lets just say to create shell emulation for now, and have ... My previous attempts to create the source below, ended with the loop ... finally resolve any issues due to this problem in PHP compatibility. ... Debug Warning: testforLinuxUser.php line 24 - stream_select: supplied argument is not a valid stream resource ...
    (php.general)
  • [Test Needed] PHP [win32] & CLI required for testing.
    ... written, lets just say to create shell emulation for now, and have ... My previous attempts to create the source below, ended with the loop ... stopping due to undefined varible, that requested for user input, the ... finally resolve any issues due to this problem in PHP compatibility. ...
    (alt.php)
  • PHP [win32] & CLI Testers needed.
    ... written, lets just say to create shell emulation for now, and have ... My previous attempts to create the source below, ended with the loop ... stopping due to undefined varible, that requested for user input, the ... finally resolve any issues due to this problem in PHP compatibility. ...
    (php.general)
  • Re: findfile?
    ... Just make sure to use escapeshellarg() or escapeshellcmd. ... descend into a directory w/ the same inode twice. ... I don't understand why PHP doesn't actually reflect the actual exec ... w/o the trouble of an intervening shell. ...
    (comp.lang.php)
  • Re: php security
    ... Well, in the shell you should take that care, for ex: ... in web server with php these directives in httpd in each virtualhost dont ... Subject: php security ...
    (freebsd-isp)