Recent content by red-team

  1. R

    Database driven website

    Thats not strictly true. Getting a php shell on the server is the second stage of an attack (the first stage finding that the site is vulnerable to an RFI attack). As mentioned before, this gives the attacker full visibility but only limited access as the shell will only have webuser rights...
  2. R

    Database driven website

    Hi, please ensure that you implement the correct security measures when developing database driven websites using mysql and php. Using 'include' with registered globals on is not recommended. Over the past few months we have found numerous issues with remote file include vulnerabilities (this...
  3. R

    Pre-launched site help needed

    Hi Ian, there appears to be a number of security related issues with the site. I will not publish here, but please PM me if you need further info. KR, Dave
  4. R

    Dedicated server

    Hi Jo, If its a managed server they will typically have the main services (dns, sendmail, ftp, ssh, apache) running. However, please remember to turn off unwanted services (ie, things you are not using) and put a service patch/update process in place from the start. We see far too many self...
  5. R

    Building a team of experts - interested?

    hi Dan, I too may be interested. I am co-founder of Red-Team Security - we're a team of ethical hackers so can offer security skills. thanks, dave at red-team dot co dot uk
  6. R

    Hosting?

    Hi Carl, Do you undertake vulnerability assessments/pen tests on your servers? If you need an independent assessment,please get in touch. KR, Dave
  7. R

    Internet Security

    Hi Ajaysolutions, please don't hesitate to get in touch if you feel your business will benefit from having access to our hacking team. Best Regards, Dave
  8. R

    Internet Security

    Hi Chris, An ethical hacker is a computer and network expert who attacks a security system on behalf of its owners, seeking vulnerabilities that a malicious hacker could exploit. Ethical hackers use the same methods as their less principled counterparts, but report problems instead of taking...
  9. R

    Internet Security

    Hi, I am co-founder of Red-Team Security Ltd. Information Security is our business, we are known as 'ethical' hackers! However, the Red-Team approach is different, we spin the security 'techno speak' into real business terms, our clients benefit from understanding risk in terms of problem...