|
|
Exploitable
Scripts
Unfortunately,
many commonly used scripts can be exploited to allow unauthorized users
into our systems. Consequently we may on occasion need to ban and consequently
disable these scripts. You can view the most current exploits on our banned-scripts
list.
===Banned
Scripts Listing:===
Prohibited
Scripts
The following scripts are prohibited on all SilverStar WebDesigns Inc.
servers:
The following scripts can be exploited by spammers:
* Matt Wright's FormMail -- all versions
* Jack's FormMail.php and its derivatives
The following scripts easily and frequently cause resource
(ab)use problems:
* UBB "Ultimate Bulletin Board" -- all versions
* YaBB + YABB se "Yet Another Bulletin Board" -- all versions
* UltimateBBS (all versions)
* Ikonboard (all versions)
* Hivemail
* PHP-Nuke
* adcycle.pl
* Greymatter (all versions)
* PHPBB
* Off-network search engines
The following activities often cause a server to be the target
of DOS attacks, or are used in conjunction with illicit activities:
* IRC bots and clients
* IRC Egg Drops & IRC related programs.(chat software)
* Proxy servers
* Hacking tools
The following scripts are used for the purpose of spamming
or sending Unsolicited Commercial E-Maill, and are not allowed for that
reason:
* any script used in the course of "domain prospecting"
* any script that queries the WHOIS databases for e-mail addresses
Additionally, the following are also not allowed on our servers:
- The Anonymizer
- lstmrge.cgi
- Shell, SSH, Telnet Scripts and Shell, SSH, Telnet Alternatives
- Any script that uses & processes a massive number of flatfiles
or large flatfile databases.
- "album.pl", coded by Mike Bobbitt.
Other scripts may be added to this list from time to time as needed.
Please feel free to contact our technical support team if you have
any questions
about whether a script is allowed on our network.
If we find banned scripts active in your account, we will disable or
remove the offending script and send you an email notifying you of
our actions.
If you are worried about a script you or one of your clients intends
to use, please send an inquiry to us with as much detail on how the
script
functions and anything else you feel we should know about the script.
Please do not ask us if "Script X" is ok without providing
any information on the script. There are thousands if not millions
of scripts
available and there are only a few of those we may be familiar with.
SERVER-SIDE SCRIPT USAGE
Our servers are –not- your testing platforms. User accounts are
on high end, live servers responsible for maintaining many accounts.
Your
server space is being provided to display your finished product to
the web - NOT for testing purposes. If you are uploading a script to
our server,
you acknowledge that you have already tested your script elsewhere
and that you know how to install the script.
Any script that the on duty administrator deems to be potentially threatening
to the overall performance of our web server will be terminated immediately
and your account access will be locked out. When scripts are executed
that are potentially harmful to the server in the long term, the offending
account will be terminated immediately without a refund of any pre-paid
fees. A termination includes the purging of all files.
===Please note the following script usage policies:
The script must use low system resources. Scripts that consume a large
amount of server memory or CPU power will be subject to termination,
and/or
additional fee.
Each user account may not use more than their fair share of system
resources at any given time. Scripts found using excessive memory or
cpu resources,
will be disabled without notice. All scripts are subject to veto power
of the system administrator(s). If a script is found to be affecting
the
other users in the shared-hosting environment - it will be reviewed
and the owner of the script contacted after its been disabled. Scripts
may
not interact with any server configuration or hardware. Users running
scripts that interact with any server configuration or any hardware
will
be subject to immediate cancellation of the user account without refund.
The script can be used and referenced from any site on the Net (i.e.
free counters, etc.) however; scripts must stay within the allowable
usage
of our system resources. Users using more resources than a single user
account is entitled to use will be assessed additional monthly charges.
The script must be executed in a timely fashion. Any script that uses
the processor for more than a few milliseconds is subject to removal.
Scripts must be secure. Unnecessarily chmoding scripts to 777 is a
policy violation. Placing scripts in a publicly viewable directory
(one without
an index.html files) is a policy violation.
Any accounts with scripts found in violation of any SilverStar WebDesigns
Inc. policy are subject to future scrutiny of all cgi by our system
administrator.
If a script is found to be harmful to the system, it will be killed
immediately and the account locked until the account owners have been
contacted. Any
time spent by SilverStar WebDesigns Inc. to kill a script and/or to
lock an account will be billed to the account at a rate of $75.00 per
hour.
Malicious scripts are subject to immediate account cancellation.
|