If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
How do I avoid unwanted GB entries.  XML
Forum Index » Support Forum
Author Message
Anonymous



Hi,

My site has been victimized by some bastards who insert scripts like the one below, which practially render the GB unusable as the GB page only shows what their script is forcing it to show.
In the past when I got a similar attack, I got rid of the script by going to the book_data table & deleting it.
I was told to disable HTML codes, which I did & I also disabled AGB Codes.
This did not prevent the insertion of the script below or it showing.
What on earth does, in the General or other settings?
I also noted that the legitimate entries, which were affected by the script being entered as a Comment to them, somehow disappeared.
I tried to look in the script source code I retrieved rom the database of affected entries and dont find the original legitimate entries, with no trace of what could be the the original entry.
That leaves gaping spaces with oly the particulars of the legitmate Guest, but with none of their original entries.
I'm just wondering how this could happen!

Please advise on how to prevent this recurring scourge.



Below is what those bastards insérted as a "comment".

Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

I'll guess you are running version 2.2 in which case a quick search of this forum would show that 2.2 has a major security exploit that is easily patched. Read the sticky thread.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
 
Forum Index » Support Forum
Go to:   
Based on the open source JForum