Re: Hack attempt

Alvin Oga <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
hi ya 

> Not really an exploit IMO. It is a feature in PHP which you should 
> disable if you don't use it. (Edit php.ini OR httpd.conf and add a 
> disable_functions directive). You shouldn't be too worried, the 'hacker' 
> can't get access to anything that the web server user doesn't have 
> access to, but don't take any chances either. (a simple rm -rf can wipe 
> you out and leave you wishing you had backups)

yup ... it's "not" critical that the script kiddie can get your /etc/shadow file
that is also accessble by the world ... or your host key files ...
	- bet you have it turned off yourself ...

always assume you've been or can be rm -rf / as root at any time ... 
and continue to implement/clean up the security policies from that assumption 

c ya
alvin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.