Tryin’ to Steal Your Autoresponder Database

I’ve noticed in my 404 logs that there were people got to one of my sites by doing a search for “index of /arp3” on Google.

arp3 is short for Autoresponse Plus, a very popular autoresponder script. (Two thumbs up and a bonus booty slap!)

There were over 1,000 results, and I clicked on a few of them to find some “arp3″ directories didn’t have a default page (ie. index.htm, default.htm, etc.) and the contents of that directory were viewable for all to see.

Luckily, the arp3 scripts and database aren’t stored in these directories, but, I suggest y’all go through your stuff and make sure you have an index file or something in there so your individual files, scripts, and graphics aren’t exposed to those who have less-than-honest intentions.



   Permalink   Subscribe By E-mail

Tags: none

2 comments:

  1. Andrew Peacock on March 30 2004

    Carmen,
    Another way to get round this is to turn off directory indexing - the people will just see a page saying:

    Forbidden
    You don’t have permission to access /arp3/ on this server.

    Your host should be able to help you do this,

    Andy

     
  2. Carmen on April 5 2004

    Hi Andy,

    I didn’t even realize they did that… checked with my host, and sure enough, if you access a directory w/out an index file, you get that “forbidden” message. Cool!

    Thanks for the info!

     


« « Win-Win: Is It Do-able? | *H* | My TIA BOT is Now On AIM » »





Meta


Categories



Copyright

© 1996-2008 MarketingChick.com

Creative Commons License

Feeds


Recent Posts


Daily Program Schedule



Link·Cetera



Blog·Cetera