• You are not logged in. | Login

Post a reply

  • Index
  •  » Discuss atricles
  •  » Discuss article: "File opening and external data. Potential vulnerability of the php-scripts"

December 20, 2006 12:30 pm

admin
Administrator
Administrator

Discuss article: "File opening and external data. Potential vulnerability of the php-scripts"

You can discuss that article here. Leave your comments

Discussed article: "File opening and external data. Potential vulnerability of the php-scripts"


 

 

April 10, 2007 3:46 pm

mastaweb99
Member
Ranks

Re: Discuss article: "File opening and external data. Potential vulnerability of the php-scripts"

PHP and mail server will have some problems

Postal server Exim breaks connection (not only has problems) when sending data forwarding events namely on that reason – you cannot send new commands if the client’s previous messages haven’t been answered “OK” by the server itself. It is going to break connection immediately after HELO and MAIL FROM. But if connection is slow there will be now forwarding effect. I cannot answer that it is so on other sites and that it is included into Exim on default.

It is supposed that forms on your site aren’t sent by the method GET, because in that case they will be stopped by that rule.

And what if an impudent hacker sends everything with POST? wink

Query journal checking

Let’s write a worm which will be searching halls and call script having a hole through itself (infinite increasing recursion up to the memory/time/sockets limit) in order to stuck hoster’s server and make admin examine the reason switching off the holes hh

Last edited by mastaweb99 (April 11, 2007 9:13 am)


 

 

April 11, 2007 9:26 am

Keeper
Member
Ranks

Re: Discuss article: "File opening and external data. Potential vulnerability of the php-scripts"

Postal server CommuniGate4.0.6 behaves in the same way. I've checked it...  smile
Can sendmail try stucking by hoster?


 

 
  • Index
  •  » Discuss atricles
  •  » Discuss article: "File opening and external data. Potential vulnerability of the php-scripts"
  • Actions
  • Top
ITCrimea. Ukraine Web Development Company. Professional Developers and Web Designers Team
Custom Web Designs, Internet Applications, E-Commerce Websites, Interactive Sites, Database-Driven Sites and Services