how to avoid kiddy scripters
Miscellaneous Forums/General Discussion/how to avoid kiddy scripters
don't allow publicly readable addresses to give out details given by phpinfo
this is very unprofessional...
Agreed. I just saw the tiniest details about what software you're using. That info gets into the wrong hands and you'll get every hole filled with an unwanted object.
The site had some pretty crucial info visible for quite some time.
Maybe this needs to be emailed too.
I don't think that was us - I assume it was the site support team.
What sensitive info is in there besides software versions (which are all standard)?
I would consider software versions sensitive as it can be pretty easy to find flaws in known versions of software.
yer damn right - thats real useful info - I honestly can NOT believe someone would make phpinfo() available from docroot
Even more troublesome if you dont think thats a problem are my login details safe with you?
Of course I think it's a problem, I'm just trying to ascertain the damage done so I can get in touch with the webhosts about it.
do yourself a favor given your track record - or should I say their track record (although it does reflect strongly on you) I would think seriously about bringing it in house...
Yeah. kind of worrying that the host would allow that info to be shown. If it was in-house you would have more control over this stuff, though I'm not sure what your speed is like over there!
I would think seriously about bringing it in house...
That's just not possible given my location.
The PHP info that was being displayed is available to anyone who knows what they are doing.
You can gain a lot of info from a site with utilities such as GFI LANGuard - you can also do this manually.
I'm not too sure anything critical was on view.
Puki, you are wierd. Anyone ever told you that?#
It's best to be safe, Seems that BRL do care about our personal details, so I'm glad it's being looked into.
Well, allright - there was a lot of info on view.
I've recaptured it - a lot of it was offscreen - I didn't browse down it at the time.
I can email it accross to BRL if they want to see it.
Puki, you are handy, you know that?#
I think you should, yeah.
I can see everything.
Even you.
woosh over your head, while the irc crowd want to shake the BAN stick at me, well come on I was being DISCRETE about what was available
I'd like to think that people who are making a compiler (an important tool) could at least deliver a secure site...
Honest I aint being funny hear, Mark really needs to choose different providers at the very least
Puki,
Yes please! Email to blitzmunter at gmail dot com.
Okay.
"puki" is on the case.
Start undressing, the large is coming.
Where am I sitting and who with? :P
I sent it from my "Michael Abrash" account - I just sent the htm.
EDIT:
Although I Larged it with FF - it might be easier to load it into IE.
IE just went freaky when FF displayed the information.
Hi,
Ok, I've talked to the web hosts about this and they assure us the site is secure.