<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Apache.org defaced &#8211; Security archive case study</title>
	<atom:link href="http://blog.sucuri.net/2010/03/apache-org-defaced-security-archive-case-study.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/03/apache-org-defaced-security-archive-case-study.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/03/apache-org-defaced-security-archive-case-study.html/comment-page-1#comment-649</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 09 Mar 2010 12:27:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=56#comment-649</guid>
		<description>In May 2000, how many PHP shells existed? In March 2010, I believe that number is a bit higher.</description>
		<content:encoded><![CDATA[<p>In May 2000, how many PHP shells existed? In March 2010, I believe that number is a bit higher.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://sucuri.net</title>
		<link>http://blog.sucuri.net/2010/03/apache-org-defaced-security-archive-case-study.html/comment-page-1#comment-650</link>
		<dc:creator>http://sucuri.net</dc:creator>
		<pubDate>Mon, 08 Mar 2010 06:16:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=56#comment-650</guid>
		<description>Joachim: I agree, it doesn&#039;t have to be root, but any user other then the apache one.&lt;br /&gt;&lt;br /&gt;As far as a php shell, they can be useful yes, but that doesn&#039;t take from the fact that you should have a deny all policy. If you see what they did in the text, they opened two different ports in LISTEN mode to do what they wanted.&lt;br /&gt;&lt;br /&gt;Plus, if you have a restricted php configuration, even a php shell can be hard to pull it off.</description>
		<content:encoded><![CDATA[<p>Joachim: I agree, it doesn&#39;t have to be root, but any user other then the apache one.</p>
<p>As far as a php shell, they can be useful yes, but that doesn&#39;t take from the fact that you should have a deny all policy. If you see what they did in the text, they opened two different ports in LISTEN mode to do what they wanted.</p>
<p>Plus, if you have a restricted php configuration, even a php shell can be hard to pull it off.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joachim Schipper</title>
		<link>http://blog.sucuri.net/2010/03/apache-org-defaced-security-archive-case-study.html/comment-page-1#comment-651</link>
		<dc:creator>Joachim Schipper</dc:creator>
		<pubDate>Mon, 08 Mar 2010 06:12:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=56#comment-651</guid>
		<description>Actually, there are plenty of ways to control a computer over port 80 - search for &quot;php shell&quot;. One could also argue that updating the web site shouldn&#039;t need root.</description>
		<content:encoded><![CDATA[<p>Actually, there are plenty of ways to control a computer over port 80 &#8211; search for &quot;php shell&quot;. One could also argue that updating the web site shouldn&#39;t need root.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

