Results 1 to 7 of 7

Thread: Please Check!!

  1. #1
    Join Date
    Dec 2007
    Posts
    70

    Default Please Check!!

    Hi.
    Don't really know where to post this, but about 4 days ago I started getting a wave of traffic, and they all used the folowing google querie..

    " inurl:top_rated.php + indexu "

    Now I know this ( dork) usually means that somewhere a vunerability issue has been posted on the boards, and the kiddies are using the "dork" to find the script, in this case IndexU..

    I have had a handful of people register "porn sites" and "pharma's" as far as I can see no damage done, i deleted the accounts.. some also came from here..
    http://www.abnobis.com/webmaster/admin_login.php

    I don't know much about this, but hopefully someone can look into this, and see what the deal is??

    Thanks

    de P

  2. #2
    Join Date
    May 2007
    Location
    NJ, United States
    Posts
    1,651

    Default

    Doing a Google search of this turns up that there was a vulnerability in version 5.0 and 5.1. If your using the latest version, I dont think this will be an issue for you.

    Maybe people are still looking for old versions of the script out there.
    FSGDAG | IndexU Hosting | Owner
    Website | NiceCoder Script Hosting and More! | Web4URL is For Sale!
    Follow Us On Twitter | FaceBook Profile | YouTube Videos

  3. #3
    Join Date
    Jun 2002
    Location
    Winnipeg Canada
    Posts
    4,913

    Default

    inurl:top_rated.php <-searches for any file "in" the URL, which means *.*/top_rated.php

    + <- pretty obvious

    indexu <- must contain the word "indexu" ie "powered by indexu"

    This is a WAY old exploit for version 5.00 and 5.01

    See http://securitytracker.com/alerts/2006/Apr/1015891.html

  4. #4
    Join Date
    Jun 2002
    Location
    Winnipeg Canada
    Posts
    4,913

    Default

    As a followup, please note that FSGDAG is incorrect in his version, 5.1 was NOT vulnerable, 5.01 is.

    Also note that this is still a popular exploit because the loser warez kiddies still keep using 5.01 because they're too cheap to pay for it and too dumb to patch it.

  5. #5
    Join Date
    Dec 2007
    Posts
    70

    Default

    Thank you for clearing this, I feel alot better now that it is an old exploit,
    Stange that it suddenly popped up again, the article must have been re-published again.. Romania, going buy the traffic I'm getting..

    Thanks Again for clearing it up.

    de P.

  6. #6
    Join Date
    May 2007
    Location
    NJ, United States
    Posts
    1,651

    Default

    Quote Originally Posted by Bruceper View Post
    As a followup, please note that FSGDAG is incorrect in his version, 5.1 was NOT vulnerable, 5.01 is.
    I must have missed the "0" when I was typing it out.
    FSGDAG | IndexU Hosting | Owner
    Website | NiceCoder Script Hosting and More! | Web4URL is For Sale!
    Follow Us On Twitter | FaceBook Profile | YouTube Videos

  7. #7
    Join Date
    Jun 2002
    Location
    Winnipeg Canada
    Posts
    4,913

    Default

    Not a problem, I just didn't want people to see the thread and panic

Similar Threads

  1. Check out this one out!
    By EBIZ in forum Sites in Action
    Replies: 2
    Last Post: 09-21-2006, 04:00 PM
  2. Please check this....
    By berto in forum v5.x
    Replies: 2
    Last Post: 01-20-2006, 07:56 AM
  3. Fixed: admin check cat-structure check
    By Frank71 in forum v3.2
    Replies: 1
    Last Post: 01-15-2006, 05:58 PM
  4. Replies: 0
    Last Post: 01-05-2006, 05:25 AM
  5. Check of the URL
    By franceliens in forum v3.2
    Replies: 1
    Last Post: 08-28-2001, 06:41 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •