RE: Fw: [Sans04] 0daymon.org
"Danny Boulineau" <[email protected]> Mon, 14 Feb 2005 09:08:27 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
As a Network Security Analyst, I would probably have a kitten if I saw this information coming from one of our systems. This page would reduced the recon requirements of hacking the system to nothing. I especially like the fact that it shows "root" as the user in the environment portions of the page. This combine with a detailed listing of the applications/versions that are running would greatly reduce the work need to "own" this system. -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of kenneth gf brown Sent: Saturday, February 12, 2005 9:49 PM To: 'Intrusions List (GCIA Practicals)' Subject: RE: [Intrusions] Fw: [Sans04] 0daymon.org let me introduce you to the phpinfo(); function used for debugging php sessions if you look REALLY close you'll see that most 80% of the information is about YOUR http session with the server... this dump used to debug php sessions is available by calling the php_info() function inside of php... whoever set that page up is calling that function... so at best it's the web admin testing something at worst they have someone with access to the public_html dir of the server most of the data is pretty much avaialable to you the end user via many different debug modes including sniffing the packets in a connection from the servers as the vast majority of this information is broadcast in headers and such kenneth gf brown ceo shadowplay.net > > Anyone know if this is intended to be this way? > > http://www.0daymon.org/ > > I normally visit http://www.0daymon.org/monitor which doesn't > currently exist. > > Either they have been hacked, they are rebuilding and don't realize > all the juicy information they are providing, or it is an attempt to > throw people off track with misinformation... > > You decide :) > > > > _______________________________________________ > > > __________ NOD32 1.996 (20050210) Information __________ > > This message was checked by NOD32 antivirus system. > http://www.nod32.com > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions