Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ What to do with XSSers? :: Archived


What to do with XSSers? :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Mon May 24, 2004 1:34 pm
Post subject: What to do with XSSers?

With email admin enabled on the error.php I frequently get emails about My_eGallery/ paths or coppermine paths files not found. My question is when you get an error email that has the XSS URL, what can we do to this person that is attempting to hack my site. When I looked at the url's information, there lied the ftp location/username/password of the hacker. Very interesting, however, If I remove the XSS files on the hacker's server am I putting myself in legal jeopardy? What if I just rename the files so they don't work and make the person troubleshoot? Has anyone reported things like this? What authorities and how did you word your letter?

- MusOX

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Mon May 24, 2004 2:18 pm
Post subject: Re: What to do with XSSers?

If they where stupid enough to put their FTP info in the hack attempt, then from my point of view you may completely empty his website and replace it with index.htm
Quote::
Site replaced by www.cybercrime.gov/ to get even with this lame hacker

and upload a .htaccess with
Code::
<filesmatch "\.(php|html|txt|inc)$">
deny from all
</filesmatch>

But ofcourse this ISN'T legal !
However i would keep my logs and inform the host about his hack attempt and that i replaced his website due to his stupidity Laughing


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Wed May 26, 2004 4:57 pm
Post subject: Re: What to do with XSSers?

Of course you should discuss legal options with a lawyer, which I'm not claiming in this regard.

However, if you are investigating your logs and in the process you come across this said hackers login information, then you certainly can use it, since he was kind enough to provide YOUR SERVER with the information. No court of law is going to say you broke in. However you are still responsible to follow any guidelines for USING the said hackers server, if they are in place. Most hackers servers I play with the rules are 'ANYTHING GOES, JUST DONT BLOW IT UP'.

So I'd be having some fun, but beware...some hackers do not have a sense of humor.

But adding a string to his XSS with this login info would be a little neat thing to do =)

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

lesa meira...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy