RE: Fw: [Sans04] 0daymon.org

"kenneth gf brown" <[email protected]> Sat, 12 Feb 2005 21:48:53 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <04ae01c5117e$f24f1e30$1a0a0a0a@gobo>
let me introduce you to the 
phpinfo(); function used for debugging php sessions

if you look REALLY close you'll see that most 80% of the 
information is about YOUR http session with the server... 

this dump used to debug php sessions is available by
calling the php_info() function inside of php... whoever set that 
page up is calling that function... so at best it's the web admin 
testing something at worst they have someone with access to the 
public_html dir of the server

most of the data is pretty much avaialable to you the end user via many 
different debug modes including sniffing the packets in a connection 
from the servers as the vast majority of this information  
is broadcast in headers and such


kenneth gf brown
ceo shadowplay.net

> 
> Anyone know if this is intended to be this way?
> 
> http://www.0daymon.org/
> 
> I normally visit http://www.0daymon.org/monitor which doesn't 
> currently exist.
> 
> Either they have been hacked, they are rebuilding and don't realize 
> all the juicy information they are providing, or it is an attempt to 
> throw people off track with misinformation...
> 
> You decide :)
> 
> 
> 
> _______________________________________________
> 
> 
> __________ NOD32 1.996 (20050210) Information __________
> 
> This message was checked by NOD32 antivirus system. 
> http://www.nod32.com
> 
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions