Author |
Message |
22/11/2004 21:32:22
|
Anonymous
|
Dear
Please Helpme, in my westbook always change my password, the htlm is off, the picture is on. A hack edit a record and change a picture for this script
<iframe src=http://es.geocities.com/hacked_esi/deface.txt>
<SCRIPT TYPE="text/javascript" LANGUAGE=JAVASCRIPT>
<!--
if (top.frames.length!=0)
top.location=self.document.location;
// -->
</SCRIPT>
and more, the scrip show the westbook record in administration mode without option "delete" or "edit"
Regards
|
|
22/11/2004 21:44:45
|
Auron
Expert
Joined: 23/06/2003 22:02:17
Messages: 1053
Offline
|
Firstly report that geocities account to geocities to shut it down and then
wait for Carbonize to have a look at this thread.
Auron
|
Visit my site @ www.ragnaru.com
Adv. Poll Install Guide NOW BACK ONLINE! (And also rather out of date I would of thought) |
|
22/11/2004 21:50:09
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
A link would be useful. Are you using Advanced Guestbook 2.2 or 2.3.1?
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
22/11/2004 22:02:12
|
Anonymous
|
2.2.
Is strange, I can reproduce this error to edit wherever record in admin mode and change the word text for the scrip.....but htlm is off????
Regards
|
|
22/11/2004 22:27:20
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
Yes as admin you can put anything you want in the entry even HTML. The script deals with any HTML tags and AGcode in a post when it is submitted.I assume you have access to your admin again? If you do then I recommmend looking in this forum for my fix for this exploit.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
22/11/2004 22:42:07
|
Anonymous
|
Ok, I read some notes in your forum, and change the line in php for
if (!get_magic_quotes_gpc()) {
$username = addslashes($username);
$password = addslashes($password);
Is all ok now?
Regards
|
|
22/11/2004 22:44:28
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
Yup thats basically the jist of it.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
22/11/2004 23:16:47
|
Anonymous
|
Many Thanks Carbonize.......
The last question, I will found and delete the fake Admin in the database?
Regards
|
|
22/11/2004 23:40:08
|
Anonymous
|
I MUST found and delete the fake administrator in my database, or his hack and pass with my administrator user?
Regards
|
|
22/11/2004 23:41:10
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
Wel if you haven't patched the exploit you can alway slog in using it. If you have patched simply restore the old session.class.php and use the exploit.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
23/11/2004 00:09:38
|
Anonymous
|
Sorry
If the patch = change the session.class.php for new scrip, why you say me "if you have patched simply restore the old session.class.php"???????.....and what is "the exploit"?
|
|
23/11/2004 11:06:05
|
Carbonize
Master
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
The exploit is simple and posted in many places online. I don't feel it is appropriate for me to post it in here though. To unpatch simply do the reverse my fix.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
|