XLWEBLIST if anyone want to take a look. Definite security hole somewhere. This is bad!!
XLWEBLIST if anyone want to take a look. Definite security hole somewhere. This is bad!!
Chris M Valk
www.xlweblist.com
Ahh, I see. They added a weblink with a huge image. Creative!
Chris M Valk
www.xlweblist.com
OK anyone else had this issue before. EDITED FOR SECURITY of their choice. This wreaks havoc with the website, but it is not a security issue, just an issue with the make up of the script. I could do this right now to anyones INDEXU script that I can tell. Has this been discussed before?
Ohh this is the hackers site http://www.radziowiel.republika.pl/
Last edited by valkster; 06-07-2004 at 06:41 PM.
Chris M Valk
www.xlweblist.com
make sure you have deleted the create_admin_user.php file from the tools folder on your serverOriginally posted by valkster
Definite security hole somewhere. This is bad!!
delete any unknown admin users from the idx_users
delete the install.php from the main folder ( where browse.php is located )
esm
"The older I get, the more I admire competence, just simple competence, in any field from adultery to zoology."
.
Tools was never uploaded, install.php was gone the second after its use. Admin folder is password protected.
Anyways here it is. The site was not hacked. A user is not required to validate themselves via email to post a link. Soooo ......EDITED FOR SECURITY....... I found the bogus user in the admin section and deleted them easily. Checked the MySQL table to make sure.
This is not a security flaw but an easy annoyance for people that do not have every link verified by an editor. I do not wish to have to do this, but I just may have to. I am sure this flaw will be exploited in the next day or so if not in the next 10 minutes on my site.
How many people let links go through without ANY verification? I am curious.
Last edited by valkster; 06-07-2004 at 06:40 PM.
Chris M Valk
www.xlweblist.com
I would not allow any submission without verification. but if you were in sort of controlled environment, then then it might be OKOriginally posted by valkster
How many people let links go through without ANY verification? I am curious.
esm
"The older I get, the more I admire competence, just simple competence, in any field from adultery to zoology."
.
Should I contact you via PM on this exploit. I do not want to dicuss it on the open forum. It is an easy exploit and I do not know how it has slipped by over the years, perhaps it hasn't.
Chris M Valk
www.xlweblist.com
i would certainly be interested in what you have found...send me a PM
esm
"The older I get, the more I admire competence, just simple competence, in any field from adultery to zoology."
.
PM away . . .
Let me know what you think via this topic.
Chris M Valk
www.xlweblist.com
esm did you want to code this fix or should I contact the author.
Chris M Valk
www.xlweblist.com
if you want to test it, I will send you the code.
esm
"The older I get, the more I admire competence, just simple competence, in any field from adultery to zoology."
.
Absolutly. I feel this is a major issue for many and whatever you came up with should be distributed in a patch ASAP.
anyways support@xlweblist.com is an email for me.
Chris M Valk
www.xlweblist.com
That fix works well. I have changed to editor approval also. I was getting some pretty bad links on their automatically.
Chris M Valk
www.xlweblist.com
yep, unless I was sure of who will be submitting links, I recommend approval first.
esm
"The older I get, the more I admire competence, just simple competence, in any field from adultery to zoology."
.
Please pm me, i'd like to know how it's hacked. Thanks.Anyways here it is. The site was not hacked. A user is not required to validate themselves via email to post a link. Soooo ......EDITED FOR SECURITY....... I found the bogus user in the admin section and deleted them easily. Checked the MySQL table to make sure.