"Fred" <newsgroup @ stupidguytalk .orgwrote in news:q6-dnViyVZbyUs7eRVn-
jQ@teksavvy.com:
Now my problem is that they are not very good/secure php
programmers, his site was hacked 3 times already , i am sure through his
.php scripts
If the cracker broke in via PHP scripts, they shouldn't have got
permissions above that of the webserver. Your second post (they cannot
modify /etc/passwd) suggests the box was rooted in which case either the
entrance vector wasn't PHP or you have locally exploitable problems too.