View Single Post
Old 08-31-2007, 02:11 PM  
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by halfpint View Post
'find suid files'
'find config* files'
'find all writable files'
'find all writable directories'
'find all service.pwd files'
'show opened ports'
There is no reason what-so-ever for a cgi script to use those commands except to hack your server.

Free scripts aren't the problem, it's when hackers put that stuff in the free script and tell you they wrote it. Don't get copies of scripts from anyone except the original source because it's their reputation they are protecting that makes the script safe.
__________________
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote