11

A reminder that upgrading your server might shut down parts of the security related components and leave services unintentionally exposed.

Upgrading should not be done without proper filtering of unwanted incoming traffic (via for example a firewall in front of the server).

Here we can see some database passwords and cryptographic secrets exposed during #debian13 upgrade due to PHP being down while the httpd was not.

#infosec #cybersecurity

you are viewing a single comment's thread
view the rest of the comments
[-] mausmalone@mastodon.social 1 points 1 month ago

@harrysintonen@infosec.exchange my old sysadmin was terrified of this specific problem so years and years ago we amended our php.ini, added a directory to the include_path outside of the website root and agreed that all functional code would live there and only presentation/formatting code would live in the website root.

It was a really solid system but it's made it a real bitch to look for outside hosting to migrate to now that my current sysadmin just doesn't /want/ to maintain a web server anymore.

this post was submitted on 11 Aug 2025
11 points (100.0% liked)

Cybersecurity

2 readers
2 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS