in

Dotnetpanel Forums

Community support forums for DotNetPanel products

Protection against PHP Shells ??

Last post 08-01-2008 4:31 PM by fadi. 0 replies.
Page 1 of 1 (1 items)
Sort Posts: Previous Next
  • 08-01-2008 4:31 PM

    • fadi
    • Top 500 Contributor
    • Joined on 07-31-2008
    • Posts 6

    Protection against PHP Shells ??

    Hi,

    I have been hosting my own site (http://drhack.net) for quite a while. But now I want to start a small hosting company.

    With shared hosting come security issues. What I have been trying to get around is protecting the server against PHP Shells (like c99 and r57 etc.)

    I read in numerous forums to disable php functions like exec(), fopen and numerous more.

    BUT this does not solve my problem. If i plant a c99 shell on my server, I can still see the 3 drive letters and a directory listings DO open up. Removing IUSR (under which PHP fastCGI is running i guess) from the permissions solves the problem of READING/WRITING content, but still directory listings for drives shows up.

    I managed to get my hands on a .dll extension of "suhosin" (Hardened PHP Project). It does show up in phpinfo() indicating that it is working BUT I have not been able to cripple the c99 and r57 shells with it. Any suggestions ?

    Any suggestions and solutions??

    Regards,

    Fadi

     

Page 1 of 1 (1 items)
Powered by Community Server (Commercial Edition), by Telligent Systems