View Single Post
Old March 8th, 2006, 5:25 PM   #8 (permalink)
Kayla
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
23,985 posts
Gave thanks: 905
Thanked 771 times
If you use any of the following scripts:

FA-PHPHosting
PHPClique
PHPCalendar
PHPCurrently
PHPFanBase
PHPQuotes

Please disable them immediately or use the fix specified below. There are serious exploits going around the net right now and have been for the past few months. All of these scripts are made by http://codegrrl.com/ and have a ridiculously easy hole in them:
"
include($logout_page);
"
This allows an attacker to include whatever code they wish into the php file and run the commands.
To avoid getting your site defaced, we recommend you either remove the protection.php file asap, or edit it and remove that line above.
__________________
Follow Surpass on Twitter, Facebook and FriendFeed
Kayla is offline   Reply With Quote