1
cydud3
Xoopsgallery init_basic.php exploit
  • 2008/1/7 9:48

  • cydud3

  • Just popping in

  • Posts: 50

  • Since: 2004/6/10


My site has been consistently hacked for several weeks now. I've tried upgrading everything to the latest. However, xoopsgallery's latest (1.3.3.9) isn't stopping the exploits from happening. Does anybody know how to fix this file? Anybody out there that had the same problem?

I'd really appreciate any help as this matter is urgent. My site is currently offline until i can fix this problem. I'm looking at my logs in realtime and hack attempts don't stop.

2
smart2
Re: Xoopsgallery init_basic.php exploit
  • 2008/1/7 10:49

  • smart2

  • Not too shy to talk

  • Posts: 129

  • Since: 2007/1/19


Hi, I don't use this module, but have you got the lastest XOOPS release installed and protector module?

3
cydud3
Re: Xoopsgallery init_basic.php exploit
  • 2008/1/7 11:10

  • cydud3

  • Just popping in

  • Posts: 50

  • Since: 2004/6/10


Yes I am running XOOPS 2.0.18 and have protector module installed. The protector module doesn't seem to catch it. It seems to be a new exploit discovered only this month. Details of the exploit is here http://packetstormsecurity.org/0801-exploits/xoopsgal-rfi.txt but since I'm not programmer, I can't really make heads or tails with it.

Any XOOPS developer have any idea how to fix? Thanks in advance.

4
irmtfan
Re: Xoopsgallery init_basic.php exploit
  • 2008/1/7 11:32

  • irmtfan

  • Module Developer

  • Posts: 3419

  • Since: 2003/12/7



5
josespi
Re: Xoopsgallery init_basic.php exploit
  • 2008/1/17 22:00

  • josespi

  • Just popping in

  • Posts: 31

  • Since: 2004/11/29



Login

Who's Online

284 user(s) are online (260 user(s) are browsing Support Forums)


Members: 0


Guests: 284


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits