By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts
Essential
These cookies enable our website and App to remember things such as your region or country, language, accessibility options and your preferences and settings.
Analytics
Analytic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
Thats not strictly true. Getting a php shell on the server is the second stage of an attack (the first stage finding that the site is vulnerable to an RFI attack). As mentioned before, this gives the attacker full visibility but only limited access as the shell will only have webuser rights...
Hi,
please ensure that you implement the correct security measures when developing database driven websites using mysql and php. Using 'include' with registered globals on is not recommended.
Over the past few months we have found numerous issues with remote file include vulnerabilities (this...
Hi Ian,
there appears to be a number of security related issues with the site. I will not publish here, but please PM me if you need further info.
KR,
Dave
Hi Jo,
If its a managed server they will typically have the main services (dns, sendmail, ftp, ssh, apache) running. However, please remember to turn off unwanted services (ie, things you are not using) and put a service patch/update process in place from the start.
We see far too many self...
hi Dan,
I too may be interested. I am co-founder of Red-Team Security - we're a team of ethical hackers so can offer security skills.
thanks,
dave at red-team dot co dot uk
Hi Ajaysolutions,
please don't hesitate to get in touch if you feel your business will benefit from having access to our hacking team.
Best Regards,
Dave
Hi Chris,
An ethical hacker is a computer and network expert who attacks a security system on behalf of its owners, seeking vulnerabilities that a malicious hacker could exploit. Ethical hackers use the same methods as their less principled counterparts, but report problems instead of taking...
Hi,
I am co-founder of Red-Team Security Ltd. Information Security is our business, we are known as 'ethical' hackers! However, the Red-Team approach is different, we spin the security 'techno speak' into real business terms, our clients benefit from understanding risk in terms of problem...