📜 ⬆️ ⬇️

phpinfo.php: incredible, but true

It was evening, there was nothing. I wrote a script to search for files phpinfo.php. 36,804 sites of the Runet were investigated, at 1,725 there was a phpinfo.php file with the phpinfo function (~ 4.69%).

As you can see, not all webmasters know the simple truth - hacking a site begins with collecting information about the server.

A similar check of foreign sites showed that our foreign colleagues are more prudent: 166,652 sites were explored, phpinfo.php was found at 3.923 (~ 2.35%).
')
% username%, and you deleted the phpinfo.php file ( temp.php , test.php ) from your site?

Side effect of the study, PHP version statistics
VersionRunetBurzhunet
5.3.3231.33%661.68%
5.3.2281.62%511.3%
5.3.1five0.29%130.33%
5.3.020.12%eleven0.28%
5.2.141347.77%77119.65%
5.2.13854.93%3809.69%
5.2.1219911.54%1884.79%
5.2.11714.12%1283.26%
5.2.101478.52%872.22%
5.2.9844.87%2626.68%
5.2.8412.38%1062.7%
5.2.7one0.03%
5.2.61669.62%3017.67%
5.2.5643.71%1142.91%
5.2.4462.67%751.91%
5.2.3130.75%220.56%
5.2.260.35%140.36%
5.2.190.52%250.64%
5.2.0311.8%380.97%
5.220.12%
5.1.61005.8%2406.12%
5.1.5one0.03%
5.1.4five0.29%180.46%
5.1.2ten0.58%200.51%
5.1.1one0.06%20.05%
5.1.0one0.03%
5.130.08%
5.0.530.17%170.43%
5.0.4five0.29%nineteen0.48%
5.0.360.15%
5.0.2one0.03%
5.0.0one0.03%
4.4.917910.38%3759.56%
4.4.8352.03%792.01%
4.4.7241.39%771.96%
4.4.6one0.06%150.38%
4.4.5four0.1%
4.4.4603.48%781.99%
4.4.3five0.29%70.18%
4.4.2eleven0.64%170.43%
4.4.1eleven0.64%eleven0.28%
4.4.020.12%130.33%
4.3.11130.75%631.61%
4.3.10392.26%691.76%
4.3.9462.67%681.73%
4.3.8one0.06%20.05%
4.3.6one0.06%30.08%
4.3.5one0.03%
4.3.420.12%170.43%
4.3.3eleven0.28%
4.3.290.52%130.33%
4.3.1one0.06%20.05%
4.3.0one0.06%20.05%
4.2.320.12%five0.13%
4.2.260.15%
4.1.220.12%20.05%
4.1.1one0.03%
Total17253923


The list of Russian sites is taken from Yandex.Catalog, the list of foreign sites from DMOZ.

UPD. Some general statistics.
In Runet from 1,725 ​​sites, the register_globals is enabled by 941 (~ 54.5%), safe_mode by 106 (~ 6.1%)
In Burzhuneta from 3,923 sites, register_globals is enabled by 1.457 (~ 37.1%), safe_mode by 195 (~ 5%)

Source: https://habr.com/ru/post/108152/


All Articles