Wrestling with the Angel of Hack

Searching a method permitting BlogBoys users to edit their AboutMe, I was hunting a php programmer. A Nucleus forum visitor pointed me toward a free script to do the job, and once downloaded and installed, it’s great and it’s terrible.

It’s great because I can copy the script anywhere into html space, then browse there, and presto I can see inside most any folder on the server. In any folder world-writable, I can copy files, make links to files, delete files, edit files. Neat.

The Angel of Hack

It’s terrible because, if I can do it, anybody can do it. Getting into a previously ‘secured’ folder and stealing the credit-card number proved way easy. If I can’t throttle this boy into acting with some restraint, he’s outta here!

This entry was posted in All. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>