Reply to Have I created a security risk?

Your name:

Reply:


Posted by Marnok.com on 01/21/08 08:31

I've had some odd activity on one of my sites.

This site tracks links to external sites. If I want to send a visitor to
http::qwerty.com/abcd it would link to go_qwerty.php?page=abcd

The go_qwerty.php then $_GET[page], records the page/datetime into a log
file and then location: to the desired page.

Person or persons unknown keep calling the go_qwerty.php and putting full
URLs as the ?page reference. These pages are from a variety of sites but
always refer to an identical looking page:

<?php echo md5("just_a_test");?>displays on page when I visit these URLS.
When I test by putting the suspicious URLs in as
?page=suspicious_url.com/blah it does nothing (tries to location: to
qwerty.com/susicious_url.com/blah)Example of a suspicious
link:http://www.nedkellypub.it/concerti/dati/olukev/orawo/Now I can't see
how this benefits them, am I missing something? Have I created some possible
way to hackers to achieve something? Is the displayed code just a cover for
some actual php going on behind the scenes?

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация