News:

Facebook killed the radio star. And by radio star, I mean the premise of distributed forums around the internet. And that got got by Instagram/SnapChat. And that got got by TikTok. Where the fuck is the internet we once knew?

Main Menu

SSH public_html vuln

Started by Joe, August 19, 2005, 11:38:39 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Joe

joe@darkside:/home/zorm/public_html$ ls
__ZORMS_FILES_HERE__

I really don't think thats supposed to be allowed.

The problem here is I can open his config.php file and get his database file. I'm too mature to use it (er, ok, I don't know how to use it), but in the wrong hands, this is bad.
Quote from: Camel on June 09, 2009, 04:12:23 PMI'd personally do as Joe suggests

Quote from: AntiVirus on October 19, 2010, 02:36:52 PM
You might be right about that, Joe.


Ergot

Quote from: Newby on February 26, 2006, 12:16:58 AM
Who gives a damn? I fuck sheep all the time.
Quote from: rabbit on December 11, 2005, 01:05:35 PM
And yes, male both ends.  There are a couple lesbians that need a two-ended dildo...My router just refuses to wear a strap-on.
(05:55:03) JoE ThE oDD: omfg good job i got a boner thinkin bout them chinese bitches
(17:54:15) Sidoh: I love cosmetology

Krazed

That's it in the httpd.conf file.

iago, get to work. I'll do it if you want.
It is good to be good, but it is better to be lucky.

iago

That's not a vuln, it's because the public_html has world-read permissions (0755).  There are 3 options to fix that:
1. Make the folder 0711.  Executable but not readable.
1. Make public html owned by the group "nobody", and assign the permission 0750
2. Make Apache SEXEC (I think), so that Zorm's stuff runs as the user Zorm, and make the permission 0700.  But that opens a whole new barrel of monkeys. 

Also, that's not "SSH" at all, even if it was a vuln it would be a permissions vuln.  SSH is the means to get a remote connection and has nothing to do with what happens once you're there. 

Joe

Either way, I can get his PHP source code. =p
Quote from: Camel on June 09, 2009, 04:12:23 PMI'd personally do as Joe suggests

Quote from: AntiVirus on October 19, 2010, 02:36:52 PM
You might be right about that, Joe.


iago

And if I get complaints about how you act on my server, I'll cut off your access. 

deadly7

Quote from: iago on August 21, 2005, 01:15:04 PM
And if I get complaints about how you act on my server, I'll cut off your access.
*coughs* iago forgot AIM already?
[17:42:21.609] <Ergot> Kutsuju you're girlfrieds pussy must be a 403 error for you
[17:42:25.585] <Ergot> FORBIDDEN

on IRC playing T&T++
<iago> He is unarmed
<Hitmen> he has no arms?!

on AIM with a drunk mythix:
(00:50:05) Mythix: Deadly
(00:50:11) Mythix: I'm going to fuck that red dot out of your head.
(00:50:15) Mythix: with my nine

iago

Quote from: deadly7 on August 21, 2005, 07:31:39 PM
Quote from: iago on August 21, 2005, 01:15:04 PM
And if I get complaints about how you act on my server, I'll cut off your access.
*coughs* iago forgot AIM already?
That's not what I meant.  He can store whatever he wants there, provided it's legal, information should be free.  I meant abusing it.