Author Topic: Security !! on 4image  (Read 3121 times)

0 Members and 1 Guest are viewing this topic.

Offline mohab

  • Newbie
  • *
  • Posts: 14
    • View Profile
Security !! on 4image
« on: May 07, 2006, 05:13:33 PM »
I get hacked on all my webpages
Puh .... now iam on searching wher it comes in and i find a suspect file in a 4 image data folder
calles nstview2.php
witch is not part of 4image
after a short google i have seen how danger is this tool.

My question  is the new 4image version resistent aginst attacks witch that tool.
Iam updating to the new version now .(to 1.7.2  form 1.7.1)
after get hacked in one week 2 times .

Ther was not just chnaging of index sites ect they install a ebay phishing site on the server.
Will talk with my server admin on mondey but i hope that after the new instalation i have fora wille
a working web.
Admin can delet or censor this post if he think its to danger for other 4image users.
Hope to get a fast help or answer to this topic .
Alll my pictuer thumbs are gone and i have to chek if the database is still intackt.
and what else is shoot down.
thank you for yor good work
Moab

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Security !! on 4image
« Reply #1 on: May 07, 2006, 07:55:51 PM »
1) googling didn't return anything about nstview2.php so I have no ide what this is.
2) did you have all bug fixes installed on your v1.7.1 before it was hacked? If so, please PM me or Jan with more details on how it was done, etc, we might have another security hole :(
What it sounds like, is that you did not have this patch installed: http://www.4homepages.de/forum/index.php?topic=11855.0
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)