If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
hack in advance westbook 2.2  XML
Forum Index » Support Forum
Author Message
Anonymous



Dear

Please Helpme, in my westbook always change my password, the htlm is off, the picture is on. A hack edit a record and change a picture for this script

<iframe src=http://es.geocities.com/hacked_esi/deface.txt>

<SCRIPT TYPE="text/javascript" LANGUAGE=JAVASCRIPT>
<!--
if (top.frames.length!=0)
top.location=self.document.location;
// -->
</SCRIPT>

and more, the scrip show the westbook record in administration mode without option "delete" or "edit"

Regards
Auron
Expert
[Avatar]

Joined: 23/06/2003 22:02:17
Messages: 1053
Offline

Firstly report that geocities account to geocities to shut it down and then
wait for Carbonize to have a look at this thread.

Auron

Visit my site @ www.ragnaru.com
Adv. Poll Install Guide NOW BACK ONLINE! (And also rather out of date I would of thought)
[Email] [WWW]
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

A link would be useful. Are you using Advanced Guestbook 2.2 or 2.3.1?

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
Anonymous



2.2.

Is strange, I can reproduce this error to edit wherever record in admin mode and change the word text for the scrip.....but htlm is off????

Regards
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Yes as admin you can put anything you want in the entry even HTML. The script deals with any HTML tags and AGcode in a post when it is submitted.I assume you have access to your admin again? If you do then I recommmend looking in this forum for my fix for this exploit.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
Anonymous



Ok, I read some notes in your forum, and change the line in php for
if (!get_magic_quotes_gpc()) {
$username = addslashes($username);
$password = addslashes($password);

Is all ok now?

Regards
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Yup thats basically the jist of it.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
Anonymous



Many Thanks Carbonize.......

The last question, I will found and delete the fake Admin in the database?

Regards
Anonymous



I MUST found and delete the fake administrator in my database, or his hack and pass with my administrator user?

Regards
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Wel if you haven't patched the exploit you can alway slog in using it. If you have patched simply restore the old session.class.php and use the exploit.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
Anonymous



Sorry

If the patch = change the session.class.php for new scrip, why you say me "if you have patched simply restore the old session.class.php"???????.....and what is "the exploit"?
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

The exploit is simple and posted in many places online. I don't feel it is appropriate for me to post it in here though. To unpatch simply do the reverse my fix.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
 
Forum Index » Support Forum
Go to:   
Based on the open source JForum