Author |
Message |
31/05/2005 15:22:11
|
Anonymous
|
Hi,
After some stupid elements repeatedly puttting code in my Guestbook which defaced it & made it inaccessible, I was made to know installing the newest version of the AGB would solve the problem as it's more secure.
The original visitor entries, to which the malicious code is entered as a comment have somehow disappeared in the 3 attacks, as they are simply not there in the database, even if I have sought them carefully before deleting the code. I wonder how that happens. Do the attackers have a way of deleting some entries?
In the 3 cases, after "cleansing" the database of the defacing code, the space where the original visitors is then empty, giving the false impression they have been edited out.
Anyway, after disabling html & AGCodes, will such/similar attackts really stop, or there are additional measures one could take?
Thanks.
|
|
31/05/2005 15:26:49
|
Anonymous
|
Let me add that after some time, the images in IE are now also showing on the uploaded website. They started after I had started posting above, but I forgot to edit the subject before posting.
|
|
31/05/2005 15:29:43
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
In all three attacks the attacker has accessed the admin section and edited an existing entry and so the existing entry has been lost to you. The problem of images not showing has been discussed before and is down to the base_url variable in admin/config.inc.php which needs setting correctly.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
31/05/2005 15:35:49
|
Anonymous
|
ok, thanks, but .... does the new version of AGB I downloaded 2 weeks ago & installed have its administrative area accessed by unknown & unauthorized people in the same way or is it now secure?
No other person has the username & password!
|
|
31/05/2005 15:37:18
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
What was your previous version? 2.2? 2.2 had a very well documented exploit that allowed anybody to login to the admin section.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
31/05/2005 15:41:28
|
Anonymous
|
Oh, I dont know which version it was. I know it was part of the available software on the cpanel at the end of 2003.
Can I assume, the admin. area is now safe?
|
|
31/05/2005 15:43:09
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
If you are running version 2.3.2 yes. If you installed via cPanel then odds are you are using version 2.3.1 as cPanel are damn slow to update and I personally blame them for a lot of sites getting defaced.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
31/05/2005 15:50:24
|
Anonymous
|
I downloaded it myself from this site & configured & uploaded the files myself. I dropped the old database files & replaced it manually with the newer version with the data added.
I did that after failing to use the "install.php" method, probably after getting something I failed to figure out right.
It kept referring to the mysql.class.php.
Anyway, thanks for the rapid responses.
|
|
|