RE: Fw: [Sans04] 0daymon.org

"Danny Boulineau" <[email protected]> Mon, 14 Feb 2005 09:08:27 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
As a Network Security Analyst, I would probably have a kitten if I saw this
information coming from one of our systems.  This page would reduced the
recon requirements of hacking the system to nothing.  I especially like the
fact that it shows "root" as the user in the environment portions of the
page.  This combine with a detailed listing of the applications/versions
that are running would greatly reduce the work need to "own" this system.

-----Original Message-----
From: [email protected]
[mailto:[email protected]]On Behalf Of kenneth gf brown
Sent: Saturday, February 12, 2005 9:49 PM
To: 'Intrusions List (GCIA Practicals)'
Subject: RE: [Intrusions] Fw: [Sans04] 0daymon.org



let me introduce you to the
phpinfo(); function used for debugging php sessions

if you look REALLY close you'll see that most 80% of the
information is about YOUR http session with the server...

this dump used to debug php sessions is available by
calling the php_info() function inside of php... whoever set that
page up is calling that function... so at best it's the web admin
testing something at worst they have someone with access to the
public_html dir of the server

most of the data is pretty much avaialable to you the end user via many
different debug modes including sniffing the packets in a connection
from the servers as the vast majority of this information
is broadcast in headers and such


kenneth gf brown
ceo shadowplay.net

>
> Anyone know if this is intended to be this way?
>
> http://www.0daymon.org/
>
> I normally visit http://www.0daymon.org/monitor which doesn't
> currently exist.
>
> Either they have been hacked, they are rebuilding and don't realize
> all the juicy information they are providing, or it is an attempt to
> throw people off track with misinformation...
>
> You decide :)
>
>
>
> _______________________________________________
>
>
> __________ NOD32 1.996 (20050210) Information __________
>
> This message was checked by NOD32 antivirus system.
> http://www.nod32.com
>
>

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions


_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions