I run my own equipment here, so I would have to say yes :)

Until someone finds another iis / php / mysql exploit any ways ....

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of James Tucker
Sent: Tuesday, August 16, 2005 2:17 AM
To: [email protected]
Subject: Re: [hlds] Possible hack

It is however the case that on most webhosts, if you store the rcon
password in the database and all of the install files in your web
folders, that any other user on the system can read your database
details, and then next read out the rcon password. For more information
on this google on apache vhosts and mysql passwords - it's a VERY common
problem.

Next, are you sure that your HSP are not repsonsible? Are the boxes
otherwise secured?

Rick Payton wrote:
> This is a multi-part message in MIME format.
> --
> You can disable it, as Mani has it's own section dedicated to rcon
commands that are allowed to run. A few stats packages require rcon
though, most notably HLstats and HLstatsX.
>
> Rick Payton, IT Support
> Morikawa & Associates
> (808) 572-1745
> http://www.mai-hawaii.com/
>
> ________________________________
>
> From: [EMAIL PROTECTED] on behalf of Alexander
> Kobbevik
> Sent: Mon 8/15/2005 9:51 PM
> To: [email protected]
> Subject: RE: [hlds] Possible hack
>
>
>
> When you run mods like mani, can't you just disable RCON?
> Or does it need to be there?

_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives, please 
visit:
http://list.valvesoftware.com/mailman/listinfo/hlds

Reply via email to