Ravens PHP Scripts: Security



Search on This Topic:   
[ Go to Home | Select a New Topic ]
 

 

PHP-Nuke Personal Menu Script Insertion and SQL Injection More about

Posted on Wednesday, February 22, 2006 @ 10:31:51 CST in Security
by Raven

SECUNIA ADVISORY ID: SA18972

VERIFY ADVISORY

CRITICAL: Moderately critical
IMPACT: Cross Site Scripting, Manipulation of data

If you are using NukeSentinel(tm) you should be protected from this exploit.
 

 

Linux worm turns on Mambo and PHP More about

Posted on Tuesday, February 21, 2006 @ 00:27:49 CST in Security
by Raven

68_andahalf_68 writes:  
Security experts today warned of a Linux network worm that exploits holes in the Mambo content management system and the PHP XML-RPC library.

Dubbed Mare.D, the worm leaves multiple backdoors on infected systems. Two of these are connectback shell backdoors that link to a remote host, while a third allows the malware's writer to access and control infected systems via IRC.

Read More

Note: 
from Raven: Check your security logs and access_logs. I have been diluged with attempts to use the Mambo hack on my site, to no avail of course. If your host does not provide you with an Apache module called mod_security, insist that they get it installed and configured. It's one of the easiest and best tools for stopping so many of these kinds of exploits :)
 

 

Finjan Warns of Valentine's Day E-card Malware More about

Posted on Wednesday, February 08, 2006 @ 10:51:43 CST in Security
by Raven

68_andahalf_68 writes:  
Finjan, a global provider of web security solutions for businesses and organisations, has warned that e-cards sent for events such as Valentine's Day, are open to misuse from those seeking to deploy malware. Some five million e-cards were sent and received on 14 February 2005, many to and from work e-mail addresses, and even more e-cards are expected this year, increasing the threat from phishing, spyware and viruses.

According to Finjan, hackers are using malicious code to try to outsmart traditional security systems such as anti-virus, firewall and Intrusion Prevention/Detection products. It said even the receipt of an e-card can be a threat and claimed that while some recipients will opt to ignore them, others will try to open them, possibly exposing an organisation to web-borne security threats.

Read More
 

 

Apache Multiple Vulnerabilities More about

Posted on Monday, February 06, 2006 @ 17:50:38 CST in Security
by Raven

68_andahalf_68 writes:  
Gentoo Linux Security Advisory Advisory Reference GLSA 200602-03 / Apache Release Date February 06, 2006 Latest Revision February 06, 2006: 01 Impact normal Exploitable remote Package Vulnerable versions... Read More
 

 

Custom 404 page with mail function More about Read More...

Posted on Friday, February 03, 2006 @ 11:37:31 CST in Security
by Raven

hitwalker writes:  
Ok we all have our nuke site running and its protected also with sentinel...right?
Okay but how many of you have more things installed like more websites or just scripts that run outside of the protection of Sentinel?
Well let me tell you this...
 Read More...
 

 

TinyPHPForum Script Insertion More about

Posted on Friday, February 03, 2006 @ 11:35:45 CST in Security
by Raven

68_andahalf_68 writes:  
Two vulnerabilities have been discovered and a security issue in TinyPHPForum, which can be exploited by malicious people to conduct script insertion attacks and disclose sensitive information. Source : http://evuln.com/vulns/14/summary.html
 



Page 84 of 102 (608 total stories) [ << | < | 79 | 80 | 81 | 82 | 83 | 84 | 85 | 86 | 87 | 88 | 89 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 513,980,262
  • Today: 99,698
Server InfoServer Info
  • Apr 29, 2025
  • 09:40 pm CDT