Programming Theory
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Codewalkers ForumsOther TechnologiesProgramming Theory

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Codewalkers Forums Sponsor:
  #1  
Old January 31st, 2005, 05:43 PM
jackwhite4501 jackwhite4501 is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: Decatur, AL USA
Posts: 2 jackwhite4501 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Send a message via AIM to jackwhite4501 Send a message via Yahoo to jackwhite4501
php security question

I've been coding in various languages for a few years and have recently begun dealing with networks and other things, so I am taking a Network Security class at my local community college. Today in class, someone says that they "found this thing where this guy wrote this C code that if you went to his site would either change your Administator password or add a new account with a given password and so he could take over your system, all just by viewing the website". When I inquired as to how this was possible, I was surprised that my teacher and a few felow classmates responded by saying this was a common and very easy to perform type practice and could be done with any programming language including PHP and Perl.

Again, I questioned them, saying that such an allowance would virtually render the internet useless, being that anyone could take over anyone's system by means of a simple website, and that you werent allowed to write to files on the client's computer without Active X or some t ype of securtiy certificate etc, and they assured me you could, so I went home and have been trying to come up with PHP to do this for the last little while to no avail.

So my question is, is this possible or is my teacher crazy like I think he is! What am I missing?? Please help me sort this out

Reply With Quote
  #2  
Old January 31st, 2005, 06:12 PM
notepad notepad is offline
Codewalkers Loyal (3000 - 3499 posts)
 
Join Date: Apr 2007
Location: Central, IL USA
Posts: 3,214 notepad User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to notepad
RE: php security question

unless they're referring to recent JPEG thing, they're crazy. i mean there's a lot of things you can do just by visiting a webpage, but certainly not setup an admin account with remote access on any visitors system.

Reply With Quote
  #3  
Old January 31st, 2005, 06:17 PM
Yian Yian is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: UK
Posts: 279 Yian User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
RE: php security question

I don't see why you want to do it anyway. Hacking for a legitimate reason is fine, but that is plain evil and shouldn't be encouraged by the teacher to be honest.

Reply With Quote
  #4  
Old January 31st, 2005, 06:20 PM
jackwhite4501 jackwhite4501 is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: Decatur, AL USA
Posts: 2 jackwhite4501 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Send a message via AIM to jackwhite4501 Send a message via Yahoo to jackwhite4501
RE: php security question

I dont want to do it, and he wasnt encouraging it, he just said it was possible, and that's all I wondered, as if it could be done, not how and show me

Reply With Quote
  #5  
Old January 31st, 2005, 06:25 PM
System System is offline
Codewalkers Novice (500 - 999 posts)
 
Join Date: Apr 2007
Posts: 665 System User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
Message Moved

Thread moved from 'PHP Coding' to 'Programming Theory' by notepad.

Reason:

Reply With Quote
  #6  
Old February 1st, 2005, 07:53 PM
Yian Yian is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: UK
Posts: 279 Yian User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
RE: php security question

Ok. I agree tho with Notepad, its just not possible with PHP. It does not have the information to do that, unless it is just getting the ip address of the client and then another program is doing the actual hacking.

Reply With Quote
  #7  
Old February 1st, 2005, 11:07 PM
lig's Avatar
lig lig is offline
"Forum Nazi"
Click here for more information.
 
Join Date: Apr 2007
Location: Jacksonville, Fl
Posts: 4,775 lig User rank is Private First Class (20 - 50 Reputation Level)lig User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 Days 13 h 47 m 18 sec
Reputation Power: 7
RE: php security question

I personally don't know but have you tried asking the PHP general mailing list? I know as a fact that many of the regular contributors deal with many security issues for their companies sites. I doubt if they will tell you how to do it but they should tell you if it at all possible.

Reply With Quote
Reply

Viewing: Codewalkers ForumsOther TechnologiesProgramming Theory > php security question


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

Request Your Free Technology Downloads!
 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

Request Your Free Technology Downloads!
 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

Request Your Free Technology Downloads!
 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

Request Your Free Technology Downloads!
 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

Request Your Free Technology Downloads!
 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 12 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek