{"id":34,"date":"2006-06-20T10:36:50","date_gmt":"2006-06-20T08:36:50","guid":{"rendered":"http:\/\/www.polymorphic.dk\/wordpress\/?p=34"},"modified":"2008-08-21T11:51:58","modified_gmt":"2008-08-21T09:51:58","slug":"hacked-damnit","status":"publish","type":"post","link":"https:\/\/www.polymorphic.dk\/?p=34","title":{"rendered":"Hacked damnit!!!"},"content":{"rendered":"<p>Jeg er sgu blevet hacked!<br \/>\nDet er ikke s\u00e5dan n\u00e5r man har slamkode p\u00e5 sin webserver.<\/p>\n<p>Kort beskrivelse: Jeg havde lavet en side ved navn main.php med en variabel ved navn id. Denne variabel var s\u00e5 filnavnet p\u00e5 den side der skulle vises, og blev vist ved hj\u00e6lp af funktionen &#8216;require&#8217;. Hackeren havde s\u00e5 konstrueret et script der prim\u00e6rt var en slags filh\u00e5ndtering, og derefter konstrueret et URL der includede dette script p\u00e5 mit site.<br \/>\nTroede ellers at php med safe_mode=on kunne forhindre det, men det kan det \u00e5benbart ikke. Men det er der s\u00e5 rettet op p\u00e5 nu, s\u00e5 nu kan det exploit ikke bruges mere.<\/p>\n<p>Reminder: brug ikke root password til andet end root login. F. eks. som mysql-password&#8230; \ud83d\ude00<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jeg er sgu blevet hacked! Det er ikke s\u00e5dan n\u00e5r man har slamkode p\u00e5 sin webserver. Kort beskrivelse: Jeg havde lavet en side ved navn main.php med en variabel ved navn id. Denne variabel var s\u00e5 filnavnet p\u00e5 den side der skulle vises, og blev vist ved hj\u00e6lp af funktionen &#8216;require&#8217;. Hackeren havde s\u00e5 konstrueret &hellip; <a href=\"https:\/\/www.polymorphic.dk\/?p=34\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Hacked damnit!!!<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-34","post","type-post","status-publish","format-standard","hentry","category-scripting"],"_links":{"self":[{"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/posts\/34","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=34"}],"version-history":[{"count":4,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/posts\/34\/revisions"}],"predecessor-version":[{"id":296,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=\/wp\/v2\/posts\/34\/revisions\/296"}],"wp:attachment":[{"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=34"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=34"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.polymorphic.dk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=34"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}