Skip to content

Comment on You thought that “This should never happen was bad”? search – eval($_GET)

Comments

Thankfully, most of these I've seen in the first four pages are for things marked as a web shell, or a security scanner, etc, so it's purposeful and not meant for serious webapp use.

Still, kind of scary to see. It's like a listening netcat piping to bash in a loop. Sure there should be a firewall in front...

If you're going to be doing any of these, there should at least be some form of authentication within the project.

Leaving this open is just hoping someone runs "rm -rf /"

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.