DwZone Forum DwZone Forum
Welcome to the DwZone-it Forum
 
  FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups  
    RegisterRegister -->   LoginLogin  
Asp Upload and Resize  
DwZone Forum Index -> Asp Upload and Resize

Moderators: AdministratorsModerators 
Hint: For improved responsiveness, use Internet Explorer 4 (or above) with Javascript enabled, choose 'Dynamic' from the View dropdown and hit 'Set Options' to save your changes.
New Topic Search for
 View     Per page     Messages Since 
Messages 771 to 780 of 860 (Total: 366) First |  Prev |  Next |  Last  
 Subject Author Date  
   Re:Aspect ratio question  
View this persons public profile  [email protected]   19:09 18 Mar 2006  
   Re:Aspect ratio question  
View this persons public profile  gianluigi   20:08 18 Mar 2006  
   Delete existing file  
View this persons public profile  [email protected]   15:02 15 Mar 2006  
   Re:Delete existing file  
View this persons public profile  gianluigi   19:15 15 Mar 2006  
   Re:Delete existing file  
View this persons public profile  [email protected]   19:29 15 Mar 2006  
   Re:Delete existing file  
View this persons public profile  gianluigi   19:43 15 Mar 2006  
   Re:Delete existing file  
View this persons public profile  [email protected]   11:18 16 Mar 2006  
   Re:Delete existing file  
View this persons public profile  gianluigi   6:51 17 Sep 2006  
    Security risk perhaps!  
View this persons public profile  [email protected]   11:17 10 Mar 2006  
 
I've recently had my server account hacked by someone uploading an asp script and executing it via the web. It deleted loads of files.

I've no explanation as to how the person got the file onto my server in the first place. All my upload pages are behind a log in, and the logs show the person didn't log in to do this.

All my upload pages also denied files such as asp aspx exe so they didn't use my upload pages to get the file on the server.

The only explanation I can come up with is somehow someone submitted a file upload form from their computer directly to the UploadFiles scripts.

Therefore is this possible? If so, I need to modify the script to only allow it to be run by users who have been authenticated by my site using a session value.

Could you tell me which file in UploadFiles that I need to protect so that it cannot be used to uploadfiles by unauthorised users.

[:(]
 
Reply to this current thread  View this persons public profile  Send Private Message
   Re:Security risk perhaps!  
View this persons public profile  gianluigi   19:57 10 Mar 2006  
Last Visit: Friday 15 Nov, 2024 4:25 pm First |  Prev |  Next |  Last  
 Login
Username:  Password:    
Read Message Read Message   Unread message Unread message
Read message [popular] Read message [popular]   Unread message [popular] Unread message [popular]
Read message [locked] Read message [locked]   Unread message [locked] Unread message [locked]
All times are GMT-1

Jump to: