Quote
Trix wrote:
G'day All,
Just letting you know PHPFusion Australia has been hacked for the 3rd time. I'm up to date with every bit of code, including the latest critical release. I'm not sure how they are doing it but PHPFusion Australia has been hacked again, with a news post. Any help with to how this is been done would be great. Until I'm satisfied with the security of the site, it will remain closed.
:(
Let me guess.
You got hacked a cpl of days ago, prolly a belgian IP address, defacing the main page with a black screen, showing the turkish flag.?
A known guy is around and pretty much known, several Email addresses and nicks are known.
What happened was, if you ask me, a little piece of scrit in a jpg image called bb.jpg probably...was with me.
With that little "image-scripting" he stole your cookie after you clicked his image after recieving a PM that his avatar was broken. That executes the script and bingo, he got the logon for your account if cookies are ON.
After that, he could just log in EVEN after you upgrading, and make a nice news...
What i mean is, it's leftovers from first hack attempt, and you have no need to worry for now, no other exploits are known as of right now, so if updated, just make a new password that you haven't used anywhere else, that'll keep him off your back for now i think.
Also this thread got our earlier exploit:
http://www.securityfocus.com/archive/...e/1/433277