Stuff that might help with the iframe thingy

You can talk about anything here, not necessarily game-related. You may also advertise here.
Post Reply
User avatar
Slasher
The FAF Forums SMEGHEAD!!! lol
Posts: 2635
Joined: Mon May 03, 2004 5:08 pm
Location: http://florida4us.com/
Contact:

Post by Slasher »

http://forums.invisionize.com/index.php ... pic=104309

http://forum.weborum.com/index.php?showtopic=4709

apparently, according to http://www.neowin.net/forum/index.php?a ... 9&t=476942 this http://www.milw0rm.com/exploits/1720 is the exploit used
The script attacks IPB up to v 2.1.5 but it could be improved to attack 2.1.6 also. The perl script can be locally executed (you just need a Perl environment in your system): it adds a post with a user account specifically added to begin the attack; the script then adds a new post with strange characters and finally it enables a remote shell. The hacker that attacked us placed a WGET command to upload a web shell (r57shell.php) that gives full control over the server, so he was able to modify the index.php file of any web application he found on our server.
Additional info: this kind of attack uses the Invision folders that need to be chmod 0777 like /uploads or similar.
http://forums.invisionpower.com/index.p ... pic=220787


Seems I've found a solution but I dunno,
http://forums.invisionize.com/index.php ... pic=107874


Last EDIT: FLIPPIN HECK!!!!! it seems they could do more than just put it on the forums, but they could send out some mass e-mail with a link in it according to http://www.wilderssecurity.com/showthread.php?t=121808

Maybe it would be a good idea to switch to SMF or PhpBB as muc as I hate those two systems...

Ok another edit:::


ITS THE GOD DAMN BLOODY TURKS THAT KEEP HITTING OUR IRC NETWORK WITH FLAMING SPAM http://www.bakakage.net/index.php?showt ... ode=linear seems they moved onto webservers now the pr@s
I do not have a signature, you must be imagining

http://florida4us.com/

Image
User avatar
Slasher
The FAF Forums SMEGHEAD!!! lol
Posts: 2635
Joined: Mon May 03, 2004 5:08 pm
Location: http://florida4us.com/
Contact:

Post by Slasher »

*COUGH* has anyone read this yet *laughs*
I do not have a signature, you must be imagining

http://florida4us.com/

Image
User avatar
Slasher
The FAF Forums SMEGHEAD!!! lol
Posts: 2635
Joined: Mon May 03, 2004 5:08 pm
Location: http://florida4us.com/
Contact:

Post by Slasher »

another thing to prevent spambots, it might be an idea to try an image verification on registration mod
I do not have a signature, you must be imagining

http://florida4us.com/

Image
User avatar
The Beatles
Fear me for I am root
Posts: 6285
Joined: Tue May 24, 2005 8:12 pm

Post by The Beatles »

We already have that, and have, since well before the spam started.
:wq
User avatar
Slasher
The FAF Forums SMEGHEAD!!! lol
Posts: 2635
Joined: Mon May 03, 2004 5:08 pm
Location: http://florida4us.com/
Contact:

Post by Slasher »

Hmm.... You don't think it could be actual people needing to get a life or something do you? or it could be some sort of bot using something on the signup page to bypass that??
I do not have a signature, you must be imagining

http://florida4us.com/

Image
Post Reply
  • Members connected in real time

    🔒 Close the panel of connected members