50 sig views
I promised you OXEO drama (pics, ++)
Collapse
This topic is closed.
X
X
-
i normally don't do that, but...
Comment
-
-
Comment
-
-
as usual, you shot off prematurely.....Originally posted by woj
50
Get in Touch on Telegram if you need a hardworker - (since 1999) - All About Me!Comment
-
Comment
-
At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.
866.ASK.OXEO,
212.812.9073
or ICQ 161954530
Thank youLast edited by PlayaPlaya; 11-20-2004, 05:29 PM.Best Regards,
Michael Volozin
Oxeo Hosting
www.oxeo.com
Direct: 212.812.9073 ext 901
ICQ: 150013894 | AIM: MikeOxeoComment
-
What are you saying? Are you denying that I viewed root on one of your virtuals? Are you saying that the screenshots are doctored?Originally posted by PlayaPlaya
At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.
866.ASK.OXEO,
212.812.9073
or ICQ 161954530
Thank you
If you are, then let's contact the owners of the sites visited and hear from them if the info in the screenshots matches or not.Comment
-
Btw,Originally posted by PlayaPlaya
At this time it appears that these infos regarding the server security are not accurate and we are investigation who is behind this post and will keep you updated. If you have any questions regarding this post or the security risk of running this script you can contact us at anytime directly.
866.ASK.OXEO,
212.812.9073
or ICQ 161954530
Thank you
Last edited by Repetitive Monkey; 11-20-2004, 05:41 PM.Comment
-
what he is saying is they have clueless system admins on staff, and they dont know how to secure their products/servers and they will be back when they hire someone and get it fixed.
aka buying time.Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.

Totally Free TemplatesComment
-
-
I missed the first page. This is gonna be funnyOriginally posted by rayadp05I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?Comment
-
-
You are in no position to be talking shit in threads about other hosts. It makes you look like an idiot, especially considering your shit was hacked twice in the same week. Retard.Originally posted by Magg
yes, they could, glad to say we're already protected against this little trick
Comment
-
From the look of it, your ServerGod webscript is using the apache user account to read user directories and files which have the wrong read/write permissions. We strongly suggest for customers not to use permissions like "chmod 777" on important directories or files to avoid any password or sensitive data leaking. The script did not compromise any of our servers or system accounts and will most likely be able to show "security problems" on every web host which allows the hosting of dynamic web scripts. If you are a customer or if you have general questions about the security risk running such a script on your website please contact us directly.Best Regards,
Michael Volozin
Oxeo Hosting
www.oxeo.com
Direct: 212.812.9073 ext 901
ICQ: 150013894 | AIM: MikeOxeoComment
-
Hold on the doublespeak. Are you trying to say that the screenshots are fake and that Server God never visited any OXEO accounts, or that a script that can read the sources and passwords for all virtual accounts isn't considered by OXEO to be a threat?Originally posted by PlayaPlaya
From the look of it, your ServerGod webscript is using the apache user account to read user directories and files which have the wrong read/write permissions. We strongly suggest for customers not to use permissions like "chmod 777" on important directories or files to avoid any password or sensitive data leaking. The script did not compromise any of our servers or system accounts and will most likely be able to show "security problems" on every web host which allows the hosting of dynamic web scripts. If you are a customer or if you have general questions about the security risk running such a script on your website please contact us directly.
The former is wrong and the latter is outrageous.Comment
-
Let me reiterate my inquiry in a manner better suited to your obligement to answer: DO YOU, AS A REPRESENTATIVE OF OXEO, CONSIDER PUBLIC VIEWING OF YOUR CLIENTS' SOURCES AND PASSWORDS A THREAT OR NOT?Originally posted by Repetitive Monkey
Hold on the doublespeak. Are you trying to say that the screenshots are fake and that Server God never visited any OXEO accounts, or that a script that can read the sources and passwords for all virtual accounts isn't considered by OXEO to be a threat?
The former is wrong and the latter is outrageous.Comment
-
This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.
If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.
I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.
This is why I use dedicated servers only.Comment
-
No solution? I understand from this that you haven't read too much into the PHP configs.Originally posted by rowan
This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.
If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.
I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.
This is why I use dedicated servers only.Comment
-
http://httpd.apache.org/docs/suexec.htmlOriginally posted by rowan
This is going to be a fundamental problem on any shared server. It's not just specific to oxeo.
If jsmith uploads a script it will have the owner as jsmith, but Apache usually runs as nobody, or www. For Apache to be able to serve (or execute) his content the files need to be world readable. Same if scripts need to create files, the directory needs to be world writeable.
I tried a simple experiment and it seems not even the owner of the file can assign the ownership to someone else... I don't think there's any real solution to this problem.
This is why I use dedicated servers only.Comment
-
Looking at the screenshots I don't see how this is 'hacking'. The most that could happen, with access to a user's home directory, is that info could be stolen. Passwords out of .htpasswd for paysites etc., content, whatever ...Originally posted by Repetitive Monkey
What are you saying? Are you denying that I viewed root on one of your virtuals? Are you saying that the screenshots are doctored?
If you are, then let's contact the owners of the sites visited and hear from them if the info in the screenshots matches or not.
So you were able to browse directories, including /root .. you didn't demonstrate that you had root priveleges on their server. You didn't demostrate that you were able to remotely compromise a machine that you did not previously have any user-level access to etc.
And I don't see what the 'trick' that someone else mentioned is. What this software does that is so '1337'. A simple 'cd' and 'ls' on the shell would work just as well... unless of course oxeo doesn't provide ssh access to it's customers.Comment
-
You mean safe mode? That causes other problems. A script can create a dir and populate it with files, but the same script is unable to delete them.Originally posted by Repetitive Monkey
No solution? I understand from this that you haven't read too much into the PHP configs.Comment
-
You don't get it. The point is that ANYONE can read ANYONES source on OXEO virtuals. If this isn't a concern for OXEO then I am shocked, and curious as to what else they don't give a shit about in regards to security and confidentiality.Originally posted by garett
Looking at the screenshots I don't see how this is 'hacking'. The most that could happen, with access to a user's home directory, is that info could be stolen. Passwords out of .htpasswd for paysites etc., content, whatever ...
So you were able to browse directories, including /root .. you didn't demonstrate that you had root priveleges on their server. You didn't demostrate that you were able to remotely compromise a machine that you did not previously have any user-level access to etc.
And I don't see what the 'trick' that someone else mentioned is. What this software does that is so '1337'. A simple 'cd' and 'ls' on the shell would work just as well... unless of course oxeo doesn't provide ssh access to it's customers.Comment
-
We have never denied that your script had access to files and directories which had the wrong permissions. We take security very seriously and running such a script on any virtual servers is a big security risk and against our terms of service. We are investigating the account which was running the software and are taking further steps to secure our servers against such web scripts.Best Regards,
Michael Volozin
Oxeo Hosting
www.oxeo.com
Direct: 212.812.9073 ext 901
ICQ: 150013894 | AIM: MikeOxeoComment
-
Ok, good. Now answer me, why didn't you do this sooner?Originally posted by PlayaPlaya
We have never denied that your script had access to files and directories which had the wrong permissions. We take security very seriously and running such a script on any virtual servers is a big security risk and against our terms of service. We are investigating the account which was running the software and are taking further steps to secure our servers against such web scripts.Comment
-
Originally posted by Superterrorizer
You are in no position to be talking shit in threads about other hosts. It makes you look like an idiot, especially considering your shit was hacked twice in the same week. Retard.
Who the hell is talking shit? I was ANSWERING A QUESTION.
RETARD.Comment
-
I have the best looking sig in this thread. I do.Comment
-
Originally posted by juicylinks
Looking for a KICK ASS TEEN SPONSOR? Check out ROYAL CASH - THE KING OF TEEN!
Incredible webmaster tools FHGs, Morphing Blog and RSS Feeds, Embedded FLV & WMV Videos.
With TOP RATIO Sites like
ATMovs.com | iTeenVideo.com | TeenSexMovs.com | TeenSexMania.com
Comment
-
Blah blah blah. You are always in hosting threads promoting your shit, talking shit about other hosts in an attempt to make yourself look like you have a clue.Originally posted by Magg
Who the hell is talking shit? I was ANSWERING A QUESTION.
RETARD.
Promoting your hosting in a thread like this makes you look like a moron.Comment
-
Youre a complete idiot, this is an open forum, my main interest is hosting, so fuck yes im going to be posting in hosting threads.
Whether Im wearing my sig or not, you'll still see my posting as I know what is going on. The sig is automatically attached to my posts, Im not going to take time and remember to unclick the button that attaches it for idiots like you who have nothing to do but criticize and hate.
I'll continue to be in hosting threads as long as there are ones being made. Sorry if you cant seem the grasp the idea of having a favorite subject.
Secondly, do you know how many hosts here on GFY are probably vulnerable to this exploit?
Installing PHP open_basedir tweak will stop users from browsing outside of their account DIR, thus negating the usefulness of this script.
Theres the easy fix.
Moron.Last edited by Magg; 11-20-2004, 08:06 PM.Comment
-
-
Sorry, I apologize. You are right, there is nothing you can do about your sig. I am not sure why I thought you were trying to spam your resold Poopah bandwidth in this thread.Originally posted by Magg

MONKEY CHECK YOUR ICQ
Let's be friends, maybe we can go to the homecoming dance together??Comment
-
-
Excuse me? This was written from scratch, by me.Originally posted by emthree
You sale cheap stolen scripts?
If you are asking whether you can buy it illegitimately then it must suck to be you.Comment
-
No, that's not what I mentOriginally posted by Repetitive Monkey
Excuse me? This was written from scratch, by me.
If you are asking whether you can buy it illegitimately then it must suck to be you.
But seeing as you killed the joke in my head, never mind
quick question:
Would it be possible for you guys to create a bulk version of SEO Buddy? I need an application which can easily check 50k-100k phrases/lines per session with ease. (My needs have nothing to do with SEO btw.)Comment
-
I still don't get what you tried to say. I must be stupid.Originally posted by emthree
No, that's not what I ment
But seeing as you killed the joke in my head, never mind
quick question:
Would it be possible for you guys to create a bulk version of SEO Buddy? I need an application which can easily check 50k-100k phrases/lines per session with ease. (My needs have nothing to do with SEO btw.)
But yes, such a SEO Buddy version is possible. I don't think there is much of a demand for it though. SEO Buddy standard has sold perhaps ten times.Comment








Sell Patches & Pills
Comment