Re: [Phpgedview-talk] attack attempt
Brought to you by:
canajun2eh,
yalnifj
From: Tastiger <tas...@sc...> - 2005-12-26 03:01:00
|
Don't blame the list - I'm not on it - and I had an attempt - but then I have 5 Postnuke sites so I'm used to these script kiddies and their antics. If you want to know why they do it - well it's because it's there and it can be done. To them it's a game and to see who can hack the most sites - doesn't matter if it's a private family tree or some huge business. I run a support group for alternative lifestyles that has been hit 5 times in the past 12 months and they still keep looking for vulnerabilities even though I have upgraded the site regularly. As for anonymity - well once you run a server, I'm afraid that is something that one must lose - if you want anonymity then don't have a web site and I'm sorry but if you are running a server without your ISP's knowledge that seems like a personal problem to me The point I am making is don't blame the list for these attempts - if you want to find sites using Phpgedview anyone can do a Google on that key word and come up with links to sites running Phpgedview. The bottom line is there was a vulnerability in the package and that hole has now been plugged - until someone finds a new hole then we do it all over again - welcome to the world of PHP :-D At 10:32 26/12/2005, you wrote: >Never-the-less, they are attacking everyone on the phpgedview list. >the list should be revised. It needs to have contact info not url info. |