PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 
Site Navigation

Home:

 
Donate o Meter
Help Keep Our Servers Online AND Our Services Free!
Make donations with PayPal!
Donat-o-Meter Stats
August´s Goal:  $400.00
Due Date:  Aug 31
Net Balance:  $47.45
Left to go:  $352.55
Donations
Luckson Aug-4
Doulos Aug-4
amber222 Aug-3
 
Please Link To Me!
 
Services Available
Quality PHP Web Host!

Great Reviews!
Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?
Need help customizing or designing scripts?
Please contact me via the Contact Us option for further details and pricing.

Link to Me

RavenPHPScripts

RavenPHPScripts

There are more Link To Me icons here.
 
Site Info v2.2.2 ©
Your IP: 38.103.63.16

 Welcome, Anonymous
Nickname
Password
Security Code:
Security Code
Type Security Code:

· Register
· Lost Password
Server Date/Time
7 August 2008 21:13:00 EDT (GMT -4)
 
Verse of the Day
 
**IMPORTANT** HoS Vulnerability Found! 
Security
Duck writes "

I would like to inform the community that I discovered a vulnerability in the Hall of Shame Module (HoS) I wrote.

It came to my attention that my server was running a script that was using up processor resources and lagging my shared host environment. The process was running under my account so I did some searching and found out there were files uploaded to the HoS punkss and punkdemo folders where files uploaded by admins are stored.

It seems they were using my server as a mail and chat relay. I still looking into the matter to figure out how they got in and how to make sure it doesn't happen again but in the meantime I wanted to inform the community so people can secure themselves as quickly as possible.

First step to do is check for any sub-folders under punkss and punkdemos and


delete ANY and ALL sub-folders you find. The sub-folders I found were named _vti_bin and ... and .a After that create an .htaccess file with the following lines in it and put in those folders.

order deny, allow
deny from all

This should protect you till I can create an update with security fixes.

Lastly check to make sure you have no cron job scheduled for which you did not create.

Also as extra measure if you did have these sub-folders existing I would recommend all admins change their passwords and also your hosting company passwords. (I don't believe my passwords were compromised as I would have found additional traces of files elsewhere but I like to err on the side of caution during these times).

Sorry I don't have an update yet but I just found out about this in this past hour and want to inform everyone right away. I will do my best to come up with an update by this weekend sometime.

Thank You,

DuckP.S. If you've found you have been compromised can you please contact me with any details that might help.

Thank you






"
Posted on Wednesday, September 26, 2007 @ 22:43:23 EDT by Raven
 
Related Links
· More about Security
· News by Raven


Most read story about Security:
PHP-Nuke *eid* SQL Injection Vulnerability

 
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


 
Options

 Printer Friendly Page  Printer Friendly Page

 Send to a Friend  Send to a Friend

 
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum