RE: [PHP] hacks we should know about

From: Date: Fri, 17 Aug 2001 09:45:43 +0000
Subject: RE: [PHP] hacks we should know about
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-63164@lists.php.net to get a copy of this message
On 17 Aug 01, at 0:08, Lawrence.Sheed@dfait-maeci.gc wrote: Not that I particularly want to turn this thread into a debate about unix security, but... > Anyone with a clue doesn't use /etc/passwd anymore *shadow password file*, > so thats kind of depreciated... While this is true a great deal of damage can still be started with access to your passwd file - gaining access to this file will, at the very least, disclose a list of valid system users, their home directory and default shell. This sort of information is useful when it comes to compromising a system - just imagine the circumstance where someone has development work sitting in their home directory - you now know the home directory. Of course, security through obscurity is never a valid approach but it's also worth trying to avoid the more obvious stuff if you can. CYA, Dave ----------------------------------------------------------------------- Outback Queensland Internet - Longreach, Outback Queensland - Australia http://www.outbackqld.net.au mailto:dfreeman@outbackqld.net.au -----------------------------------------------------------------------

« previous php.general (#63164) next »