Re: [Full-disclosure] e107 latest download link is backdoored



Speaking of silent fixes...





On Mon, Jan 25, 2010 at 7:48 PM, Chris Travers <chris@xxxxxxxxxxxxxxxx>wrote:

On Mon, Jan 25, 2010 at 2:58 AM, Bogdan Calin <bogdan@xxxxxxxxxxxx> wrote:
Hi guys,

The latest version of e107, version 0.7.17 contains a PHP backdoor.
http://e107.org/e107_files/downloads/e107_v0.7.17_full.zip

Looks like the e107 team has removed this file, and reviewing the code
in the cvs repository this code does not appear there.

Best Wishes,
Chris Travers

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages