<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "New hack for version 2.3.1"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "New hack for version 2.3.1"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>New hack for version 2.3.1</title>
				<description><![CDATA[ The following code was submitted to my guesbook (version 2.3.1) which allowed a hacker to take over the index.php page:<br /> <br /> r00t_System<br /> &lt;div id=\"post\" style=\"position: absolute; top: 0; left: 0; width: 1024; height: 2500; z-index: 1; overflow: auto\"&gt; &lt;table border=\"0\" width=\"100%\" bgcolor=\"#000000\" height=\"100%\" cellspacing=\"5\" cellpadding=\"5\" valign=\"top\"&gt;&lt;tr&gt;&lt;td width=\"100%\" valign=\"top\"&gt;<br /> &lt;font style=\"color: #ffffff\"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;r00t_System ownz here by M&lt;u&gt;aMa&amp;nbsp;&lt;/u&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;#rsy - irc.gigachat.net - <a class="snap_shots" href="mailto:olinuxbrasil@bol.com.br">olinuxbrasil@bol.com.br</a>&lt;br&gt;&lt;img src=\"http://www.regionofdoomforum.com/Upload/userfiles/r00t/r00t.jpg\" border=0\"&gt;<br /> &lt;br&gt;admin attention on configuration!&lt;/font&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;<br /> <br /> When I looked at the source code on that particular page, I saw the following code:<br /> <br /> &lt;a href="admin.php?action=edit&amp;amp;tbl=gb&amp;amp;id=164&amp;amp;record=123&amp;amp;session=7fcc9a9fbecadc97ff8cb1ef8fb88d1b&amp;amp;uid=1"&gt;edit&lt;/a&gt;&lt;br&gt;<br /> &lt;a href="admin.php?action=del&amp;amp;tbl=gb&amp;amp;id=164&amp;amp;session=7fcc9a9fbecadc97ff8cb1ef8fb88d1b&amp;amp;uid=1"&gt;delete&lt;/a&gt;<br /> <br /> Is there a fix for this. I was able to regain the page through the php control panel but I'd rather not have to do that again.<br /> <br /> Please reply to kenroar at yahoo.com]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11342.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11342.php</link>
				<pubDate><![CDATA[Sun, 31 Oct 2004 09:17:53]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title>Sample of hack</title>
				<description><![CDATA[ I found another sample of this hack at <a class="snap_shots" href="http://www.stadiumguide.com/guestbook/" target="_blank" rel="nofollow">http://www.stadiumguide.com/guestbook/</a><br /> <br /> Apparently this individual is searching out all html enabled guestbooks with version 2.3.1]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11343.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11343.php</link>
				<pubDate><![CDATA[Sun, 31 Oct 2004 09:36:40]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Some hackers search these forums, so it's not a good idea to put the actual code here.  <br /> <br /> Also, if you have an account, you can edit a post, but I don't think guests can do that.<br /> <br /> The Admin does not monitor this site, so I don't think there is any way to delete it.<br /> <br /> With that comment the hacker left, "admin attention on configuration", it sounds like <br /> they are warning you to make sure you disable html.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11345.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11345.php</link>
				<pubDate><![CDATA[Sun, 31 Oct 2004 10:36:01]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ What I really want to know is how they did it. If I know how they did it, I can take precautions. I have not given any write permissions on my templates. Somehow they were able to hijack the page- possibly using html coding in the message box.<br /> <br /> If you do a search on r00t_System you will find hundreds of websits this guy has hacked. He has nothing better to do with his time, I guess.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11429.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11429.php</link>
				<pubDate><![CDATA[Tue, 2 Nov 2004 01:42:14]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Well, I'm thinking it is because html was enabled.  They sent the code in a post.<br /> <br /> Carbonize is looking into this to see if that's the case.  I assume when he knows for sure he'll let us know.<br /> <br /> In the meantime, I would urge everyone to turn off html.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11430.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11430.php</link>
				<pubDate><![CDATA[Tue, 2 Nov 2004 01:52:52]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yup if you allow HTML the guestbook allows ALL HTML.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11433.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11433.php</link>
				<pubDate><![CDATA[Tue, 2 Nov 2004 11:50:09]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]Yup if you allow HTML the guestbook allows ALL HTML.[/quote]<br /> <br /> To re-iterate that its not like phpBB which blocks [b]ALL[/b] HTML tags <br /> and allows only allows certain ones that you specify.<br /> <br /> Auron]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11436.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11436.php</link>
				<pubDate><![CDATA[Tue, 2 Nov 2004 19:11:01]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yup so can I be bothered writing code to only allow certain HTML or do I remove all HTMLM functionality from the update I am making ?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11437.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11437.php</link>
				<pubDate><![CDATA[Tue, 2 Nov 2004 19:13:39]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I think we should forget about html.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3799/11443.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3799/11443.php</link>
				<pubDate><![CDATA[Wed, 3 Nov 2004 01:06:38]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
	</channel>
</rss>