Chi Kien Uong
Geranienstraße 30
71034 Böblingen
Deutschland / Germany
|
If you are not registered or logged in, you may still use these forums but with limited features.
Show recent topics
|
|
|
Author |
Message |
21/04/2005 22:00:33
|
Anonymous
|
Hi,
My site has been victimized by some bastards who insert scripts like the one below, which practially render the GB unusable as the GB page only shows what their script is forcing it to show.
In the past when I got a similar attack, I got rid of the script by going to the book_data table & deleting it.
I was told to disable HTML codes, which I did & I also disabled AGB Codes.
This did not prevent the insertion of the script below or it showing.
What on earth does, in the General or other settings?
I also noted that the legitimate entries, which were affected by the script being entered as a Comment to them, somehow disappeared.
I tried to look in the script source code I retrieved rom the database of affected entries and dont find the original legitimate entries, with no trace of what could be the the original entry.
That leaves gaping spaces with oly the particulars of the legitmate Guest, but with none of their original entries.
I'm just wondering how this could happen!
Please advise on how to prevent this recurring scourge.
Below is what those bastards insérted as a "comment".
|
|
22/04/2005 05:45:56
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
I'll guess you are running version 2.2 in which case a quick search of this forum would show that 2.2 has a major security exploit that is easily patched. Read the sticky thread.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
|
|
|
|
Based on the open source JForum
|