You are here: Re: Security vulnerability question « PHP Programming Language « IT news, forums, messages
Re: Security vulnerability question

Posted by Good Man on 10/10/07 19:38

phpCodeHead <phpcodehead@gmail.com> wrote in
news:1192043448.321346.169560@y42g2000hsy.googlegroups.com:

> In my code, 'to' parameter should be of a value ?to=sales or
> ?to=engineering generated through a hypertext link. Although,
> manually
> entered parameter values such as ?to=getAllCustCreditCardNums or
> ?to=anyOtherJibberish have been coded to accomplish absolutely
> nothing,
> I have been intrigued by an error report received through customized
> error reporting code inthe app. It reports an error event in which an
> URL was manually entered in as a value of 'to'. The error report
> returns global array
> values at time of error. .... and it is all because I "failed" to
> initialize a variable... :)
>
> My question(s) is ...
> What is being attempted here?
> Is this a new exploit attempt?

It looks like a redHat machine was compromised by a script (kiddie), and
that machine is trying to find further exploits on other machines (like
yours!)

It's not particularly new, it seems lots of people are getting it
http://www.google.ca/search?q=hut2.ru+cs.txt
http://security.pigstye.net/staticpages/index.php/index

As long as your script is correctly coded to ignore anything other than
what you're expecting it to get (as you have done), there's nothing to
worry about.

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация