PDA

View Full Version : Awkward files in customavatars?!


Taragon
10-24-2008, 09:24 PM
Hello,

Currently I have set to store all avatars to my server.

Could someone identify these files perhaps? And how to avoid this in the future?

/customavatars
drevelation.php
Inbox.php
unknowntask.php

/customavatars/ise/ise/ise/ise/hour/halifax-online.co.uk/secure/_mem_/formslogin.asp/
.htaccess
Drop3PostLaunch.php
finish.php
index.html
index11.gif
rurCaptureContactDetails.php
rurCaptureSecurityQuestions.php
updatepersonaldetails.php

Lynne
10-24-2008, 10:23 PM
Those files don't look like they are up to any good at all. - Capture Contact Details? Capture Security Questions? Drop 3 Post (on) Launch? Have you been having any site problems lately?

Taragon
10-24-2008, 10:34 PM
Hi Lynne,

No, none at all. Also I just recently made this alteration. Those who had/have access I completely trust.
I somehow seem to be unable to remove them, therefore I contacted my host.

Since I just set/changed my avatar storage type, could you please confirm I had to chmod my /customavatars to 777?

SEOvB
10-24-2008, 10:56 PM
777 or 755 will work depending on your hosting configuration

Lynne
10-24-2008, 11:08 PM
You may want to ask your host for help to find out how those files got onto your server. Do it soon because logs get rotated and you may not have them around for much longer.

Amenadiel
10-26-2008, 03:50 AM
it seems to me someone uploaded hacking php scripts using the avatar upload capabilities and or used the 777 permissions to move files there.

can you post the content of drevelation.php ?

GreigScott
10-31-2008, 04:48 PM
Somepeople for starters you cant trust. and ask your host.