Re: Asp.net in a shared hosting environment

From: Defender (1_at_nospam.nospam)
Date: 08/29/04

  • Next message: Paul Roberts: "Required permissions to set Process.PriorityClass in Win 2003 serv"
    Date: Sun, 29 Aug 2004 00:11:46 -0400
    
    

    So first hacker would need to upload the executable to your server. Then he
    would have to upload .aspx server script. Then execute it. There is certain
    responsibility that developer has to take for the secure code and admin for
    the administration of secure server.

    fyi:
    php has: exec()
    perl: <!--#exec cmd=" /etc/passwd" -->
    etc

    "Harold Mackey" <mackeyha2@hotmail.com> wrote in message
    news:BD561D1C.23A7%mackeyha2@hotmail.com...
    >I found this article to be a bit disturbing
    >
    > http://www.developer.com/net/asp/print.php/3318911
    >
    > Anyone have comments, or know of links out there that provide more
    > information on the problem?
    >
    > Thanks
    > Hari
    >


  • Next message: Paul Roberts: "Required permissions to set Process.PriorityClass in Win 2003 serv"

    Relevant Pages

    • Re: File Upload - Security Issues
      ... You want to upload a file for what reason and ... these viruses have less chance of being able to execute (even if succeeded ... :> file and what pitfalls you see re: security might be helpful on this ... :>: files to an IIS server that doesn't have MS Office actually installed? ...
      (microsoft.public.scripting.vbscript)
    • Re: File Upload - Security Issues
      ... uploaded and the user could upload any or all of these in theory. ... There is no one product that can give you 100% security, ... > Code doesn't execute in local memory space unless remote user has rights ... > You don't have MS Office installed on the server. ...
      (microsoft.public.scripting.vbscript)
    • Re: File Upload - Security Issues
      ... You want to upload a file for what reason and you ... these viruses have less chance of being able to execute (even if succeeded ... > file and what pitfalls you see re: security might be helpful on this end?! ... files to an IIS server that doesn't have MS Office actually installed? ...
      (microsoft.public.scripting.vbscript)
    • Re: Is there a way to validate a pdf file?
      ... If by executable the OP meant being able to upload a "pdf" that was in ... actuality a php script that could be run on their server, ... and 2, it won't execute. ... the server won't see it as a script. ...
      (comp.lang.php)
    • pure-ftp nologin
      ... I have a server running FreeBSD 6.3. ... # If you want to enable PAM authentication, ... AnonymousCanCreateDirs no ... # Disallow anonymous users to upload new files ...
      (comp.unix.bsd.freebsd.misc)