Looking to hire a security expert

Discussion in 'Security' started by dfarook, Mar 10, 2009.

  1. #1
    I am looking to hire someone who knows how test my web site for security.

    Question: Can someone access a website get into the server and change a posted document that is in a PDF format? I believe this happened on my website. I posted a complete pdf for public viewing only to find some of the content is changed every week. I didn't think it was possible since a pdf is almost like a photgraph.

    Don
     
    dfarook, Mar 10, 2009 IP
  2. MH-Andy

    MH-Andy Peon

    Messages:
    30
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I'm no security expert,

    But you should check the raw http access logs and see any expliot is being used, they cant modify the PDF im sure they would have to download it, change it, then re-upload it - It's easy enough with a shell (c99.php etc..)

    They most probably have a shell on your server hidden in a directory somewhere, from that they can browse the contents of your server, edit, modify and upload
     
    MH-Andy, Mar 14, 2009 IP
  3. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #3
    check the logs first on who is logging in. also check that if any suspicious process is running as nobody
     
    olddocks, Mar 14, 2009 IP
  4. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Check the permissions of the file, could be writable for all users.
     
    SSANZ, Mar 17, 2009 IP
  5. olddocks

    olddocks Notable Member

    Messages:
    3,275
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    215
    #5
    no! any pdf can be manipulated with free pdf libraries using php.
     
    olddocks, Mar 17, 2009 IP
  6. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    100% agree. PHP has capable of manipulating and processing more and more types of files.
     
    justdoit1, Mar 18, 2009 IP
  7. baonhi41

    baonhi41 Peon

    Messages:
    141
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Not expert but I can help you basically for free. Send me a PM
     
    baonhi41, Mar 18, 2009 IP