If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
Hacker attack on the guestbook!  XML
Forum Index » Support Forum
Author Message
Anonymous



high@ll

someone deleted all the entries from my guestbook yesterday!

i just changed the password again, extremely complicated now (it was a little bit too easy before)

can someone tell me, how i can prevent this in the future?

is it normal, that i have to enter the password again and again in the administration menu although i just didn't klick anything for just two minutes?


please help me...


greetings stratos
Anonymous



You should seriously read the forum posts before posting. First, ensure you have html disallowed. Second, make sure you are not vulnerable to SQL injections. Seriously, it's not difficult, but if you dont bother then you can type anything for the username and let the password be ') OR (''=' and it logs you in to the admin section.
Anonymous



thanks Anon

sorry i'm not a crack, what are SQL injections and how can i prevent them?


greetings stratos
amber222
Graduate

Joined: 07/05/2004 21:13:07
Messages: 586
Offline

I just bumped the post with Carbonize's fix for version 2.2. If you are using this version, apply the fix or, better yet, upgrade to version 2.3.1.
 
Forum Index » Support Forum
Go to:   
Based on the open source JForum