Anonymous Monk has asked for the wisdom of the Perl Monks concerning the following question:
I have a virtual private server with a web host. I have a few of my websites hosted there. The VPS is just for my own websites and I have not given ssh access to anyone else. I would like to think my passwords are quite secure. But someone was able to put a php file in the document root of one of my websites with both the owner and group being 'nobody' - This could seem like the file was put there via http. I am a novice. I have given below the listing of the file (flight.php). My web host says to look for scripts through which this could have been done. I would appreciate your help and if you can refer to some material that I can read to understand how I can secure my perl scripts.
-rw-r--r-- 1 subhasri subhasri 0 Aug 19 11:44 .htaccess -rw-r--r-- 1 subhasri subhasri 546324 Aug 19 11:45 error.php -rw-r--r-- 1 nobody nobody 2318 Aug 20 11:00 flight.php
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Phishing question
by MidLifeXis (Monsignor) on Aug 25, 2011 at 10:04 UTC | |
by Anonymous Monk on Aug 25, 2011 at 13:16 UTC | |
by MidLifeXis (Monsignor) on Aug 25, 2011 at 13:25 UTC | |
|
Re: Phishing question
by Anonymous Monk on Aug 25, 2011 at 09:39 UTC | |
|
Re: Phishing question
by locked_user sundialsvc4 (Abbot) on Aug 25, 2011 at 13:30 UTC | |
by Anonymous Monk on Aug 26, 2011 at 03:52 UTC | |
by Anonymous Monk on Aug 26, 2011 at 17:40 UTC | |
by MidLifeXis (Monsignor) on Aug 26, 2011 at 18:13 UTC |