Page 1 of 1

MOC or any other techy's..

Unread postPosted: Sat, 4 August 2012, 11:34 am
by genieswish
could someone translate what this gobbledygook means pls?

A directory traversal (or path traversal) is to exploit insufficient security validation / sanitization of user-supplied input file names, so that characters representing "traverse to parent directory" (using ../ in many cases) are passed through to the file APIs. By default, all references to the above values (and some similar ones) are blocked unless otherwise whitelisted (unblocked).

someone has tried to hack my site 3 times in the last hour (different pages) using a directory traversal - what are they trying to do??

Re: MOC or any other techy's..

Unread postPosted: Sat, 4 August 2012, 12:49 pm
by MOC
What is Directory Transversel attack?

Directory Traversal is an HTTP exploit which allows attackers to access restricted directories and execute commands outside of the web server's root directory.

The goal of this attack is to access sensitive files placed on web server by stepping out of the root directory using dot dot slash.
genieswish wrote:By default, all references to the above values (and some similar ones) are blocked unless otherwise whitelisted (unblocked).

By the sound of it, it sounds like your settings are relatively ok with type of exploit being tried on your hosting. I have people running bots and scripts on my sites almost daily it seems so just keep an eye on things and don't stress because it happens all the time, kids just wanting to play with bots and scripting usually genie :roll:

Re: MOC or any other techy's..

Unread postPosted: Sat, 4 August 2012, 2:31 pm
by genieswish
sheesh, can't imagine why anyone would want to get into my files LOL - scares the crap outta me when i dont understand a word of it!

Re: MOC or any other techy's..

Unread postPosted: Sat, 4 August 2012, 3:08 pm
by MOC
they do it just to say they did it, cause they like playing with bots and scripts, it's a hobby like any hobby and they call it 'hacking' lol. most of them cant write their own scripts they not talented enough so they just modify power scripts to do something they want to do, like just stuff something up for someone! don't worry just monitor things, look for new files or directories on your server, keep learning and you'll be fine.

Re: MOC or any other techy's..

Unread postPosted: Sat, 4 August 2012, 3:45 pm
by genieswish
i found a new url? www.showmesomemoneydotcom/success-tips/?replytocom=192 I didn't create that! what does the bit on the end ?replytocom=192 mean

Re: MOC or any other techy's..

Unread postPosted: Sun, 5 August 2012, 1:49 am
by MOC
It's a normal link for blogs that allow 'reply to comments'.

Check shoutmeloud link there is some good info there that might help with the current google changes too..

http://www.shoutmeloud.com/how-to-fix-r ... press.html