PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Virgin_Steel
Worker
Worker


Joined: Sep 30, 2004
Posts: 108
Location: Sf

PostPosted: Sat May 13, 2006 4:48 am Reply with quote Back to top

OK...just the other day while i was drivin` my car i got a call from my host company and they said to me that someone has tried to send 58 000 e-mails with spam through my site.When i arrive at home and looked up to the logs of the server and Ip_Tracker i realized that the hole in my security was AVATARS foldrer!!! How the hell this 'hackers' have been created a 'aa.php' file that sends this thousends of e-mails ? Is there a security fix for this? I don't know..only .jpg & .gif allowed in this folder or?
I know this folder has to be CHMOD-ed to 777 for users to be able to upload their avatars...
Please, help me. I'm using php-Nuke 7.0 , but my phpBB has been upgraded with almost every security fix that comes out...
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 4653

PostPosted: Sat May 13, 2006 6:12 am Reply with quote Back to top

There is a known exploit that can take advantage of remote avatars/signatures if you have html enabled in the forum config, though I think this has been fixed I would only recommend that BBCODE is enabled.

Whilst it is possible the are activating their script via the forum, do not discount other modules you might have such as SPChat, vWar, Gallery and anything that allows remote uploads.
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum