vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Awkward files in customavatars?! (https://vborg.vbsupport.ru/showthread.php?t=194460)

Taragon 10-24-2008 09:24 PM

Awkward files in customavatars?!
 
Hello,

Currently I have set to store all avatars to my server.

Could someone identify these files perhaps? And how to avoid this in the future?

/customavatars
drevelation.php
Inbox.php
unknowntask.php

/customavatars/ise/ise/ise/ise/hour/halifax-online.co.uk/secure/_mem_/formslogin.asp/
.htaccess
Drop3PostLaunch.php
finish.php
index.html
index11.gif
rurCaptureContactDetails.php
rurCaptureSecurityQuestions.php
updatepersonaldetails.php

Lynne 10-24-2008 10:23 PM

Those files don't look like they are up to any good at all. - Capture Contact Details? Capture Security Questions? Drop 3 Post (on) Launch? Have you been having any site problems lately?

Taragon 10-24-2008 10:34 PM

Hi Lynne,

No, none at all. Also I just recently made this alteration. Those who had/have access I completely trust.
I somehow seem to be unable to remove them, therefore I contacted my host.

Since I just set/changed my avatar storage type, could you please confirm I had to chmod my /customavatars to 777?

SEOvB 10-24-2008 10:56 PM

777 or 755 will work depending on your hosting configuration

Lynne 10-24-2008 11:08 PM

You may want to ask your host for help to find out how those files got onto your server. Do it soon because logs get rotated and you may not have them around for much longer.

Amenadiel 10-26-2008 03:50 AM

it seems to me someone uploaded hacking php scripts using the avatar upload capabilities and or used the 777 permissions to move files there.

can you post the content of drevelation.php ?

GreigScott 10-31-2008 04:48 PM

Somepeople for starters you cant trust. and ask your host.


All times are GMT. The time now is 10:50 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01058 seconds
  • Memory Usage 1,714KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (7)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete