The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
![]()
There has been a security hole in Photopost VBGallery that the authors have not publicized so if any of you are running this script, please go look at this thread for your own good.
Anyone with VBGallery should read this thread and fix the hole. http://www.photopost.com/forum/showt...=134835&page=3 After getting hacked, I found out that the weak link is the Photopost VBGallery. The hackers were uploading PHP files disquised at media files and the server recognises them as php when testing the upload and then runs it and sets up their command center. I got hit twice and a LOT of other people running this script are getting hit. Here (from my log) is how the second hacker found us by searching for Photopost vbgallery *** Exploit Details removed. Please do not post such details in public *** This is the exact time the board went down. There are a bunch of other entries of him doing his work but at least now I know where they are getting in. It will make it a lot easier to keep them out If you have Photopost VBGallery, shut it down until you fix this hole. I wouldn't even post this here but the authors seem reluctant to notify their users about this threat and meanwhile these kids are mowing down sites by the dozens. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|