Originally posted by Laylah
View Post
Announcement
Collapse
No announcement yet.
Spam through Contact Us Form
Collapse
X
-
Originally posted by smiffy View PostIs this true that hackers can exploit any of the .pl files to gain full access to the web space? I've removed my MF00001.PL files as I though this was the only loophole!
Comment
-
Originally posted by smiffy View PostIs this true that hackers can exploit any of the .pl files to gain full access to the web space? I've removed my MF00001.PL files as I though this was the only loophole!
Originally posted by Darren B View Postchanging the ftp passwordsFergus Weir - teclan ltd
Ecommerce Digital Marketing
SellerDeck Responsive Web Design
SellerDeck Hosting
SellerDeck Digital Marketing
Comment
-
[QUOTE=fergusw;325614]The only exploits I have been aware of were a possible XSS injection (Cross Site Scripting) as well as the mailform issue, however these issues were both well documented and resolved with subsequent releases of the software. To my knowledge no up-to-date version (7,8,9,10 or11) of Actinic perl files are open to direct exploitation in this way.
As far as I'm aware I'm running the most current V7 software, but I've suffered from the mailform issue. Have I missed an update?
Comment
-
AFAIK
1. The mailform issue is seperate from the cross scripting issues.
2. I'm not sure Actinic fully released V7 with the latest XSS fixes as I think it was sometime after V8 was released. It might have been available by request only from Actinic.
Mike-----------------------------------------
First Tackle - Fly Fishing and Game Angling
-----------------------------------------
Comment
-
Actinic no longer support v7, so I guess that loophole is not fixed in the latest v7 patch.
We have just had one of our clients v7 sites sending out a few thousand spam emails. Looking at the logs, the MF00001.PL was attacked at the same time (repeatedly executed hundreds of times).
I'm in the middle of upgrading his site to V11, but wont launch till March 1st.
I'll try and change the perl numbers and hopefully that'll delay the bot a little while until they rescan the site.
Comment
Comment