Announcement

Collapse
No announcement yet.

Security Expliot with PHPLiveHelper

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Security Expliot with PHPLiveHelper

    Anyone using PHPLiveHelper on their website - if you recently upgraded from v1.8 to 2.0 - or are running ANY version earlier than 2.0 - contact us offlist for important information to prevent hackers uploading trojan's to your server.

    Hosting companies - you may need to scan your servers for IRC Bots uploaded by this expliot. Contact us offlist for file details.

    For security purposes, we will not post the explioted filenames or methods. We just want to advise those that are using this product how to secure it.

    PHPLiveHelper's development team fixed the expliot in v2.0, however they were not aware of an issue we brought to their attention and are now changing their upgrade instructions to eliminate the issue.

    #2
    Vic,

    Good comment and yes, you are very correct.

    Users need to get an upgrade or at least change the defualt directory where the software is located.

    It's a great time to look at ALL php scripts a user/site owner has. phpBB and a few others have been the focus of injection scripts (hacks) and the fix is easy...keep your PHP scripts updated.
    dotCOM host - MIVA Premier Hosting Partner
    "High Speed Hosting... High End Support"
    ____________________________________________
    Steven Daris
    dotCOM host / Red Apple Media
    San Diego, CA 92103
    1.888.321.6239 US & Canada
    http://www.dotcomhost.com
    http://www.redapplemedia.com
    [email protected]

    Comment


      #3
      Originally posted by Vic - WolfPaw Computers
      Anyone using PHPLiveHelper on their website - if you recently upgraded from v1.8 to 2.0 - or are running ANY version earlier than 2.0 - contact us offlist for important information to prevent hackers uploading trojan's to your server.

      Hosting companies - you may need to scan your servers for IRC Bots uploaded by this expliot. Contact us offlist for file details.

      For security purposes, we will not post the explioted filenames or methods. We just want to advise those that are using this product how to secure it.

      PHPLiveHelper's development team fixed the expliot in v2.0, however they were not aware of an issue we brought to their attention and are now changing their upgrade instructions to eliminate the issue.
      Good job Vic
      Dan

      Girlfriends Lingerie - "Keeping It Sexy!"
      Sexy Lingerie - Twitter - Facebook- Pinterest - YouTube

      Comment


        #4
        Good Job Vic
        Dan

        Girlfriends Lingerie - "Keeping It Sexy!"
        Sexy Lingerie - Twitter - Facebook- Pinterest - YouTube

        Comment

        Working...
        X