2 Dec 17:00
writing of php file to webserver owned directory -- can mod-security prevent this?
John covici <covici <at> ccs.covici.com>
2007-12-02 16:00:53 GMT
2007-12-02 16:00:53 GMT
Hi. I had an attack this morning where someone was able to execute lwp-download for a text file and then rename it to a php file and then he had some fun. The php file was called a.php and all the comments are in a different character set, maybe Eastern European. I have client-ip followed by the download command and in the next request by the mv command. These were in the audit.log part B of each request. Can mod-security prevent such a thing? Any assistance would be appreciated. -- -- Your life is like a penny. You're going to lose it. The question is: How do you spend it? John Covici covici <at> ccs.covici.com ------------------------------------------------------------------------- SF.Net email is sponsored by: The Future of Linux Business White Paper from Novell. From the desktop to the data center, Linux is going mainstream. Let it simplify your IT future. http://altfarm.mediaplex.com/ad/ck/8857-50307-18918-4
RSS Feed