|
|
Choosing A Webhost: |
Re: Serious issue: msg#00004cms.phpwebsite.devel
> From: Brady Bellinger > > Are sites that only allow trusted, registered users also affected by this issue? > To my knowledge our site does not allow anonymous users to submit announcements. > > Thanks, > > Brady Hi Brady, That might make a little bit of difference, but this is serious enough that you should do the patch. If you are running and older version or have a heavily modified installation, just add the new code in index.php to your index.php. Also do not be fooled by comments such as "normally only apache/nobody user access is attained". Such access is the first step of almost all breakins as it gives enough access to run a privelege escallation exploit. I would like to hear some other opinions on this as well, but that's currently my take on the situation. Best regards, Jim Wilson ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: [ezForm] Howto get a value selected on the select-formelement, Steven Levin |
|---|---|
| Next by Date: | Re: Serious issue, Brady Bellinger |
| Previous by Thread: | Re: Serious issue, Shaun Murray |
| Next by Thread: | Re: Serious issue, Brady Bellinger |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |