News:

Want to get involved in developing SMF, then why not lend a hand on our github!

Main Menu

Please Help, Hacked by Turkish hackers.

Started by xinnek, May 14, 2006, 10:21:03 AM

Previous topic - Next topic

MegaV1

if i let guest posts, how does this problem work?

winrules

Quote from: MegaV1 on May 27, 2006, 05:05:49 PM
if i let guest posts, how does this problem work?
The problem is with allowing guests to shout, not post.


winrules
SMF Developer
               
My Mods
Please do not PM me for support.


MegaV1

okay, if the guest shouts, how does this problem work and how do i prevent it from being used on my forum?

winrules

It is only a security problem is you use TinyPortal (or maybe the Ultimate Shoutbox Mod, I'm not sure if that was affected, too). Look here for the fix.


winrules
SMF Developer
               
My Mods
Please do not PM me for support.


MegaV1

i'm using SimplePortal + Ultimate Shoutbox

Harzem

Ultimate Shoutbox also has a fix, but I don't know where it is released.

They exploit the vulnerability, by using

<script language="javascript">location="www.forwardsite.com"</script>

as their poster name in shoutbox. The completely correct code is not the one above, for security reasons :)

MegaV1

by using that code, what do they hope to achieve?
i don't understand

Harzem

They simply redirect your page to another site, where they usually have the "hacked by" thing.

forsakenlad

Eren "forsakenlad" Yaşarkurt
SMF Friend & Former Team Member

Advertisement: