Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sécurité insuffisante dans le dossier data #293

Closed
bazooka07 opened this issue May 14, 2018 · 0 comments
Closed

Sécurité insuffisante dans le dossier data #293

bazooka07 opened this issue May 14, 2018 · 0 comments
Assignees
Labels
changes new features

Comments

@bazooka07
Copy link
Collaborator

Si un attaquant parvient à déposer ou à faire déposer un script PHP dans le dossier data ou un de ses sous-dossiers, il est possible d'en lancer l'exécution.

Pour éviter ce désagrément, modifier le fichier .htaccess à la racine de ce dossier comme suit :

options -indexes
<Files "*">
	SetHandler default-handler
</Files>

Avec un peu de social enginering, c'est possible de faire déposer par le webmaster un script PHP époustouflant auquel il n'a rien compris

@haruka-7 haruka-7 self-assigned this Jun 17, 2019
@haruka-7 haruka-7 added the changes new features label Jun 17, 2019
haruka-7 pushed a commit that referenced this issue Jun 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
changes new features
Projects
None yet
Development

No branches or pull requests

2 participants