OK...just the other day while i was drivin` my car i got a call from my host company and they said to me that someone has tried to send 58 000 e-mails with spam through my site.When i arrive at home and looked up to the logs of the server and Ip_Tracker i realized that the hole in my security was AVATARS foldrer!!! How the hell this 'hackers' have been created a 'aa.php' file that sends this thousends of e-mails ? Is there a security fix for this? I don't know..only .jpg & .gif allowed in this folder or?
I know this folder has to be CHMOD-ed to 777 for users to be able to upload their avatars...
Please, help me. I'm using php-Nuke 7.0 , but my phpBB has been upgraded with almost every security fix that comes out...
There is a known exploit that can take advantage of remote avatars/signatures if you have html enabled in the forum config, though I think this has been fixed I would only recommend that BBCODE is enabled.
Whilst it is possible the are activating their script via the forum, do not discount other modules you might have such as SPChat, vWar, Gallery and anything that allows remote uploads.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum