Web Design Is The Word

 


PHP Security

Posted in Umbrella news by kevingallagher on the May 25th, 2007

If you are using PHP on your website we ask that you please read the following carefully. We have noticed a significant number of PHP websites are being compromised due to vulnerable PHP code. Spammers are scanning millions of websites on the Internet looking for PHP scripts that can be exploited to send spam. When they find a script that has a loophole they send thousands of email messages through the script, often taking down the website or severely impacting website performance. 

Generally these loopholes exploit code using parameters from a form being passed straight to a mail command or page include without being checked for extra characters. These problems include line feeds in email names and addresses, or including any page passed to the script. When we find a site that is being exploited we often have to disable scripting for the whole site or at least for the compromised script (if we can identify it), this can mean unexpected downtime for your website. This problem affects all PHP websites available on the Internet, not just ones hosted by Umbrella. 

This issue can often be resolved by upgrading to the latest version of the script or in the case of custom scripts asking your developer to close the loophole that has been exploited. We would ask that you carry out a security audit on your PHP scripts to ensure they are not vulnerable. Whilst we cannot carry out this process for you if you do have any questions then please feel free to contact Umbrella.

Thank you for your assistance with this matter. 

3 Responses to 'PHP Security'

Subscribe to comments with RSS or TrackBack to 'PHP Security'.

  1. jc penney said,

    on September 25th, 2007 at 10:51 pm

    http://jc-pennys.blogspot.com/ jc penney


  2. on September 26th, 2007 at 9:22 am

    http://hometown.aol.com/maskhalloween halloween masks

  3. Radford said,

    on March 1st, 2009 at 11:06 pm

    aaah, is there an update to this?

Leave a Reply


AWeber Demo
Less Work - More Sales
Sound good? AWeber's unlimited follow up autoresponders increase sales, lower costs, build lasting customer relationships, and increase your profits!
Find out how with Unlimited Autoresponders.