lavalair script holes
Collapse
X
-
the php word is still there..just do a pregmatch of the word..like if(preg_match("/php/i",basename($file))) then invalid extension..Can also use htaccess trick..Just use some head..Originally posted by robzky View Posthackers change the extesinn of c99shell script.. E.G. a.php.Jar or a.php.nth
Leave a comment:
-
improper or **** configuration of apache and the mime types thats one reasonOriginally posted by ranzit2 View Posti dnt understand how a php file will work if its extension changed to jar.,plz explain
basic protection is mod_security so use that
plus there are many many ways of hacking the script i sent my last lava script before i went to my current one to some european security team and had an audit put on it, cost me 320 euros to do and the results i got were unbelievable
i'm not going to share the results reason being the cost it was for me was a lot 1/4 of my monthly wage and a bet many others will do the same here also, but if you are using it don't piss off anybody who can "actually" and not the people here and around other such communities saying i'll hack this and that, i'll murk ya site biatch etc etc
no offence to them people but if anyone had the sense to actually send it to a 3rd party you wouldn't be using it any longer
just my 2 fat Australian cents there
Leave a comment:
-
hackers change the extesinn of c99shell script.. E.G. a.php.Jar or a.php.nthOriginally posted by kiLLeR-eyEd_14 View Posti don't know more about c99shell..i think it's a php script right?so, just don't allow php files to be uploaded..or if you want, block php files using your htaccess as what ozzie has posted here..
Leave a comment:
-
Ozzie will hack your site a piece of piss lolOriginally posted by kuklux View PostOzzie try to visit my site and try to hack my session or my members sessions and see what message will prompt! tnt.
Leave a comment:
-
Ozzie try to visit my site and try to hack my session or my members sessions and see what message will prompt! tnt.
Leave a comment:
-
u better check all of ur folders, think y some script here are hacked from other site? Even they dont know ur cpanel login details but uploaded the backdoor key, you wil be hacked... im only sharing this coz im a victim of this. and the hacker forgot to remove that tools.Last edited by tres; 11.09.09, 23:28.
Leave a comment:
-
Leave a comment:
-
Yeah the secret mafia of lava will concrete your feet and sink u to the bottom of the ocean???? wtf?
Im just saying that people wont pin-point the holes as it will cause a mass hacking spree
Leave a comment:
-
i don't know more about c99shell..i think it's a php script right?so, just don't allow php files to be uploaded..or if you want, block php files using your htaccess as what ozzie has posted here..Last edited by kiLLeR-eyEd_14; 11.09.09, 10:53.
Leave a comment:
lol
Leave a comment: