Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - New Turkish Hacker Trick.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

New Turkish Hacker Trick.

 Post Reply Post Reply Page  <1 4567>
Author
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 30 September 2005 at 10:00am
There are built in features for users to upload there own avatars and images, but these are disabled by default and you are warned that if you enable them it is a security problem.

It's like with many things in computing, you have to decide if you want functionality or security.

The best solution is to disable users uploading their own images and if they want to use their own avatars they can link to one of their own web space, this would be the more secure way of doing it.
Back to Top
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 30 September 2005 at 5:04pm
ok...i understand.... i'm bad for have to decide to denied avatars upload ...but if is necessary...
Back to Top
Ali Bilgrami View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 April 2005
Location: Pakistan
Status: Offline
Points: 492
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ali Bilgrami Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2005 at 7:23am
hi
i changed the path for image uploads
 
and tried to upload an image and this is what i got
 
 

Microsoft VBScript runtime error '800a004c'

Path not found

/forum2/functions/functions_upload.asp, line 80

i changed it to http://www.mywebsite.com/somefolder/upload
and it says line 77 and invalid character
 
so does it mean that my service provider has that security of no write permissions to IUSR_ account???
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 03 October 2005 at 7:35am
The path must be a relative server path, URL's will not work.
Back to Top
Ali Bilgrami View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 April 2005
Location: Pakistan
Status: Offline
Points: 492
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ali Bilgrami Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2005 at 4:38am
ive asked my server guyz and they have told me that they do not use this IUSR scheme....so in this context my site and server are safe :) also ive upgraded to 7.92 :)
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2005 at 6:03am
If they don't use the IUSR scheme then they use some other matching scheme otherwise people would be unable to view your site.

What ever scheme they use you need to be sure that they don't allow write permissions on those files and directories viewable through a web browser.
Back to Top
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2005 at 10:59am
And you should never assume your site is safe.  The best secured sites in the world can be hacked given enough effort.  It's very difficult to evaluate the relative security of a site that is one among hundreds hosted on the same machine.
 
If your host recognizes the difference between a server-wide IUSR account and user accounts unique to each virtual domain, then you're probably safer than most of us.  But, did the host leave the default "Full Control" rights for the "Everyone" group in the C:\Windows\System32 folder?  If so, any user able to view your site can do anything they want to that critical system folder.  The list of exploitable mistakes is endless.
 
The most that can said about a host that uses virtual domain hosting best security practices is that WHEN one of the sites on the machine gets hacked, only that site can be hacked and the hacker can not then use that site to hack the machine or other sites on the machine.
p.s. I'm not affiliated with Web Wiz Guide in any way. I'm just an average Web Wiz user repaying my debt for the use of their fine forum by trying to help other Web Wiz Guide users.
Back to Top
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2005 at 1:51pm
WebWiz Site where are hosted ? your host take also .IT domain ?
Back to Top
 Post Reply Post Reply Page  <1 4567>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.