Re: Can anybody communicate with the operating system without the php server?



Fro wrote:
Sure, they could hack your server, either just your personal account data or
else the entire server.
You say that they can hack:
1. My server.
2. My personal account data.
3. The entire server.
What do you understand under "personal account data"? The operating
system?

To remove "ambiguity" I should say that I do not have "my personal
server". I use a hosting which gives a php-server which has many
users.

But it's 100 or 1000 times more likely that they
breached security through a file upload, if you use a reputable third-party
host.
It is 100 or 1000 times more likely than what?


I agree with Mason - it's much more likely your upload script has holes in it than someone hacked your server.

Since you're using a shared host, it's remotely possible that they came in through another site on the same host. But that's unlikely, unless your hosting company has no idea what they're doing and other sites on the host are either hacker sites or don't know what they're doing. But any reputable host will prevent that from happening.

--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@xxxxxxxxxxxxx
==================

.



Relevant Pages

  • gdm hangs
    ... gdm will hang 9 of 10 times when logging out. ... with or without the client having been connected to the Server. ... # Timed login, useful for kiosks. ... Must output the chosen host on stdout, ...
    (Debian-User)
  • problem with sendmail in solaris 9
    ... names that should be exposed as from this host, ... # save Unix-style "From_" lines at top of header? ... # work recipient factor ... # SMTP STARTTLS server options ...
    (SunManagers)
  • Re: Add new cluster and use existing LUNs?
    ... Storport driver and Powerpath on all of our SAN host servers so we are trying ... In the end I think that I may play it cautious and create a new RAID group, ... > varied activity (DBMSes, Messaging Server, File Server, Web Servers, ... Some of the physical spindle limitations can be addressed through the SAN ...
    (microsoft.public.sqlserver.clustering)
  • Log corruption on multiple webservers, log analyzers,...
    ... Related RFC´s about Internet Host Names convention: ... To succesfully attack a server with “ILLC” technique is mandatory that web ... a machine with a host name as "123.123.123.123" makes a request ... wouldn't appear in the access log file. ...
    (Bugtraq)
  • UPDATE weird sendmail problem on Solaris 9 (fwd)
    ... I was asked to supply info about my sendmail config and my nsswitch.conf ... names that should be exposed as from this host, ... # list of locations of user database file ... # SMTP STARTTLS server options ...
    (SunManagers)