SikStyles
Senior Member
DeathCult
Posts: 894 Reputation: 29
35 / /
Joined: Jan 2005
|
O.P. RE: Website being hacked
quote: Originally posted by segosa
Tell him this.
You can't go blindly using include() on anything the user can input into the URL. That's just asking for trouble.
If you give a URL to PHP's include() function and URL wrappers are enabled (most servers) then it'll download and include it into the page.
If you write a PHP script and stick it inside a .txt file, upload it to your server and put its URL into the xd= line the contents of that file will be executed on the victim's server with the httpd's permissions.
If he coded the site, or his friend did, then he should know that that's a security hole.
thanks a bunch Segosa
i'll tell him that
You're still breathing? Why?
Get off the cross, the wood is needed.
|
|