Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - New Turkish Hacker Trick.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

New Turkish Hacker Trick.

 Post Reply Post Reply Page  <1 567
Author
Ali Bilgrami View Drop Down
Senior Member
Senior Member
Avatar

Joined: 14 April 2005
Location: Pakistan
Status: Offline
Points: 492
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ali Bilgrami Quote  Post ReplyReply Direct Link To This Post Posted: 04 October 2005 at 2:53pm
-borg- & JJLatWebWiz this is what my server guyz sent me
 
By default IUSER account is disabled accross the server. Only your usage has READ/WRITE permissions on your folders. For webaccess, you are limited to READ access as well unless you specify a few folders specificly for Write access.

If your account has a script that can be used to hack your site, it will be limited to  your account, not to the whole server.

So as long as you keep all of your software up to date, there is nothing to worry about.

now what do u think?? Smile although i asked them about the everyone group permissions again lets see when do they reply to that. i'll let u know when they do :) 


Back to Top
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 07 October 2005 at 3:37pm
Ali Bilgrami -
 
It sounds like your host has a healthy understanding and respect for security, which is more than half the battle Thumbs Up.  Even if they have left the Everyone account as default, your site contents should be safe from a hacker attacking from a different domain on the same server.  If the Everyone account still has full control on the system32 folder, a hacker could crash the operating system, but your site should still be safe even though it would be offline.  Once your host recovers the OS, your site will be intact.  That's because it's currently impracticle for a hacker to escalate their rights assuming the host has hardened the other attack vectors like Microsoft's FTP service, disabling unnecessary services, and installing the bundles of OS service packs and hotfixes.
 
If you haven't made any read/write permission changes to your account folders, you can test a little of your hosts claims by changing the uploads folder in the WWF Admin control panel to blank, and each of the forum sub-folders and seeing if you can upload test files through WWF.  Any folder that you can upload to explicitly allows the anonymous user of at least your domain to upload anything.  That should only be true of the uploads folder(s) and the folder that holds the Access MDB.
 
 
p.s. I'm not affiliated with Web Wiz Guide in any way. I'm just an average Web Wiz user repaying my debt for the use of their fine forum by trying to help other Web Wiz Guide users.
Back to Top
 Post Reply Post Reply Page  <1 567

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.