Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: testing compiled php |
|---|---|
| Date: | Mon, 21 Aug 2006 09:39:02 +0100 |
I think you missed my point, they need an almost root mysql user to access the database so that they can create and drop databases and tables and they need their document root directory to be writable by the webserver as they create random files all over the place.
Robin
Hi, there are few websites which claims to decode the encrypted php files but they wil charge you some amount.they also have a demo option which u can use. another thing is tht mysql does not need to be run as root and whole root directory does needs to be writable. regards, -CF http://www.secgeeks.com
On 8/19/06, Robin Wood <dninja@gmail.com> wrote: > Hi > I've been asked to install a compiled php app on a server I manage and > I'm not happy with the way it has been built so I'm looking for a way > to do check through the code but, as it is compiled I can't just view > it. > > Is there an easy way to decompile php? I've had a google and found a > couple of services offering to decompile individual pages but nothing > for full sites. > > I'm not sure what compiler was used but this app requires the zend > optimizer to run. > > Things I'm not happy about: > Needs full write access to the whole of its web root, it seems to > create files and directories all over the place. > Needs almost root mysql access, the only thing it doesn't need is > grant privileges! It created databases when you add new data into the > site. > I've found XSS on the authors site and on this app - I've reported > this to the author who after claiming to be big on security asked me > to explain XSS and still hasn't fixed the problem a few weeks later. > > I've got permission to test the app but I'm not being paid for it so > I'd much rather do a code review than full test on each page, that way > I can patch anything I find or make other provisions to protect from > the problem. > > Robin > > ------------------------------------------------------------------------- > Sponsored by: Watchfire > > Watchfire was recently named the worldwide market leader in Web > application security assessment tools by both Gartner and IDC. > Download a free trial of AppScan today and see why more customers choose > AppScan then any other solution. Try it today! > > https://www.watchfire.com/securearea/appscancamp.aspx?id=701500000008VnB > -------------------------------------------------------------------------- > >
-- ting ding ting ding ting ding ting ding ting ding ding i m crazy frog :) "oh yeah oh yeah... another wannabe, in hackerland!!!"
------------------------------------------------------------------------- Sponsored by: Watchfire
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: testing compiled php, crazy frog crazy frog |
|---|---|
| Next by Date: | Re: testing compiled php, Robin Wood |
| Previous by Thread: | Re: testing compiled php, crazy frog crazy frog |
| Next by Thread: | Administrivia: Move the list?, Andrew van der Stock |
| Indexes: | [Date] [Thread] [Top] [All Lists] |