Author |
Message |
newbie
Regular


Joined: May 03, 2004
Posts: 62
Location: USA
|
Posted:
Thu May 13, 2004 5:59 pm |
|
Hi,
I'm so sick of these hack attempts that ... well, I don't know.
Chatserv, Raven ... thank you for all you do ... I've been following it all for awhile since I was hacked about 3 weeks ago with that stupid "God Admin" deal.
I patched my site ... I installed the HackAlert deal ... and all went well ... UNTIL today ... I get two notices from the protector module ... that a url ... I don't know if I should post it here or not ....
Anyway ... a url was posted ... so I went to go check it out .. and it brings up MY name and my encrypted password!!!!!!!!!!!!!!!!!!!!!!!!!!
What the HELL am I supposed to do now?
Sorry.
Okay ... taking a chill pill
Thanks for the help. |
_________________ Darla
Only registered users can see links on this board! Get registered or login! |
|
 |
 |
sixonetonoffun
Spouse Contemplates Divorce

Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Thu May 13, 2004 6:19 pm |
|
Why don't you pm the url in question to chatserv or me and we'll sort it out asap for everyone.
Is that while running the most recent version note the update date? |
|
|
|
 |
newbie

|
Posted:
Thu May 13, 2004 6:29 pm |
|
Hi,
I pm'd the url to chatserv.
He said that it works to view the pw through phpmyadmin ... but I'm waiting on a response to see what, if anything they can do with it ... or if they're just letting me know they're still around ...
Thanks! |
|
|
|
 |
newbie

|
Posted:
Thu May 13, 2004 6:30 pm |
|
Oh,
Forgot to say ... yep, I've got the most recent update and patched version of 7.2.
Haven't done the 7.3 upgrade yet.
Thanks again. |
|
|
|
 |
sixonetonoffun

|
Posted:
Thu May 13, 2004 6:32 pm |
|
lmao I was just thinking you won't be able to pm the url if the hackalert onsite here is catching it! |
|
|
|
 |
newbie

|
Posted:
Thu May 13, 2004 6:39 pm |
|
LOL,
So far, so good  |
|
|
|
 |
sixonetonoffun

|
Posted:
Thu May 13, 2004 7:56 pm |
|
For anyone wondering we tested this against the last update to the UNION hack prevention and it catches this one too.
Note the code in the default PHPNuke7.3 mainfile.php does not catch the latest UNION exploits on its own.
So be sure you are using the latest version:
Code:
$queryString = strtolower($_SERVER['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString");
die();
}
|
|
|
|
|
 |
newbie

|
Posted:
Thu May 13, 2004 8:11 pm |
|
Just wanted to say "Thanks" real quick.
I really appreciate the help ... and how fast you all reply!
Take care. |
|
|
|
 |
chatserv
Member Emeritus

Joined: May 02, 2003
Posts: 1389
Location: Puerto Rico
|
Posted:
Thu May 13, 2004 9:25 pm |
|
7.3 is missing a patch in the Downloads module which is covered in PHP-Nuke Patched 2.4, what comes as a surprise is that it does not stop it by default, to my understanding 7.3 includes UT |
|
|
|
 |
sixonetonoffun

|
Posted:
Thu May 13, 2004 9:30 pm |
|
Yeah I just peeked its the buggier UT3 code though which was only good for about an hour before an update was released. |
|
|
|
 |
Raven
Site Admin/Owner

Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Fri May 14, 2004 10:59 pm |
|
sixonetonoffun wrote: | For anyone wondering we tested this against the last update to the UNION hack prevention and it catches this one too.
Note the code in the default PHPNuke7.3 mainfile.php does not catch the latest UNION exploits on its own.
So be sure you are using the latest version:
Code:
$queryString = strtolower($_SERVER['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString");
die();
}
| | Doo-dah, Doo-dah  |
|
|
|
 |
newbie

|
Posted:
Sat May 15, 2004 7:50 am |
|
|
|
 |
Raven

|
Posted:
Sat May 15, 2004 11:10 am |
|
Not yet - still gone but took a break from the hospital. Not sure when I'm going back. Maybe tomorrow - Maybe next week  |
|
|
|
 |
|