Fw: About malicious java sciprt running...

From: GUs (rootz_at_fibertel.com.ar)
Date: 12/10/03

  • Next message: B $B%$%9%^%$%k: "Re: About malicious java sciprt running..."
    To: <s970501@ku.edu.np>, <security-basics@securityfocus.com>
    Date: Tue, 9 Dec 2003 20:14:55 -0300
    
    

     In fact, if Global Variables is set to "YES" in your php config, then you
    have a big problem.
    Because de $a variable could be i.e.:
    http://host.com/file.php?var=../../../../etc/passwd
    This issue depend of your entire system configuration.
    1) Restrict the permissions that your script could invoque.
    There is a few lines in your config file to do that.
    2) Chrooting APACHE will give you more security and it is a
    good practice in web-server security even if an "atacker" has compromised
    your system. But there is always more :).
    3)Read http://www.linuxsecurity.com/articles/documentation_article-5788.html
    to know about secure prgramming techniques over php.
    There is a lot of techniques to protect your webserver and good
    secure programming, but this is "security-basics" and all this could be
    enough for now.
    Keeps your eyes open and your mind free. Review 1000 times your codes.
    Protect your network.
    Watch out with your Routers. Patch it all. :)
    cheers,

    (EthNic)
    Gustavo T.
    IT-Student & Tech support.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: B $B%$%9%^%$%k: "Re: About malicious java sciprt running..."

    Relevant Pages

    • RE: 192.168.x.x oddities
      ... When configuring firewall rules, it is imperative to lock networks to ... Bad config: ... At a glance, this looks safe, because we're using pessimistic security. ...
      (Security-Basics)
    • [opensuse] Fixed: (was Re: SECURITYQ: anyone experience w/using sockd (dante-server)?)
      ... I get all the config options 'right', ... It was a bad SECURITY configuration, ... yet and had turned auditing off. ... I think AppArmor might explain some of my other oddities -- ...
      (SuSE)
    • Re: Workgroup Manager: screwed up home directories
      ... It sounds like you configured your server as an Open Directory Master. ... I can login on the one account that was created locally (aka: ... Config" manual with 90% of it related to how to disable something on the ... very little about actual security. ...
      (comp.sys.mac.system)
    • Re: [2.6 patch] remove smbfs
      ... the first five mount attempts - tell them to switch to CIFS. ... config JFFS2_FS_POSIX_ACL ... implemented by security modules like SELinux. ... mounts may be less secure than mounts using NTLM or more recent ...
      (Linux-Kernel)
    • Re: [2.6 patch] remove smbfs
      ... the first five mount attempts - tell them to switch to CIFS. ... config JFFS2_FS_POSIX_ACL ... implemented by security modules like SELinux. ... mounts may be less secure than mounts using NTLM or more recent ...
      (Linux-Kernel)

    Loading