Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Turkish hacker.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Turkish hacker.

 Post Reply Post Reply Page  <12
Author
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 01 November 2005 at 3:22pm
I don't think most web site admins are going to have the option to disable ADODB.Stream as it would probably have to be disabled for entire server hosting hundreds of other sites.

However, I think the security flaws in ADODB.Stream actually compromise the client when combined with flaws with Internet Explorer. The ADODB.Stream/IE security flaws allow a web page to execute script on the client machine in the Local Machine internet zone.

The Turkish hacker utility that I've seen doesn't exploit any unintentional security bugs or flaws. It will work on ANY server that uses ANY enabled version of the ADODB.Stream and no correction of unintensional flaws therein will hinder this hacker utility. Only server administrators using best practice security configurations can stop this utility from working.

Even a flawed ADODB.Stream is working with the security rights of the anonymous web user, so ADODB.Stream can be used to upload files ONLY to folders to which the anonymous user has such permission.

Of course, there are always other security flaws and poor server configurations that could be exploited to change that, but WWF is required or even useful for any of this hacking. And don't let your host tell you that by using WWF, it was your fault that the server was compromised.
p.s. I'm not affiliated with Web Wiz Guide in any way. I'm just an average Web Wiz user repaying my debt for the use of their fine forum by trying to help other Web Wiz Guide users.
Back to Top
 Post Reply Post Reply Page  <12

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.