How Kyivstar deceives and profits from its customers

One user once told me that he received an SMS on his phone with a message stating that the subscription fee for a daily package had been charged instead of a monthly one, although there was money in the account to charge the monthly one.

Continue reading “How Kyivstar deceives and profits from its customers”

File Integrity Check Script (size+mtime)

I recently showed an example of a file integrity check script that calculates SHA-256 hashes. However, if the files are large and 100 gigabytes or more, this will naturally put a significant load on the disk system. Therefore, if this is critical and slows down other processes, I will give an example of a simple script that works much faster. It simply checks the file size and mtime (modification time). However, it is worth considering that, unlike the SHA-256 hash, an attacker can specify the mtime of a new, substituted, infected file similar to the old one.

Continue reading “File Integrity Check Script (size+mtime)”

Setting up open_basedir

I strongly recommend configuring the open_basedir parameter, which lists directories beyond which PHP scripts cannot traverse, as open_basedir is not specified by default.
If open_basedir is not specified on the web server, then, for example, Path Traversal vulnerabilities can lead to access to all files on the server that have “read by others” permissions, such as /etc/, /var/, and other directories.

Continue reading “Setting up open_basedir”