c99

Your phpBB Version: 2.0.22
phpBB Type: Integramod 141
MODs: No
Your knowledge: Basic Knowledge
Board URL: http://mweva.com
PHP Version:
MySQL Version:
What was done before the problem appeared?
Nothing. Basic plain jane install. Only thing different is the sites banner
What was done to try to solve the problem?
Reset permissions for uploads
De.scription and Message
Hello all. a while back my site was hacked and the ONLY mods installed were activity mod and AUCG.
I uploaded a fresh site, on my server, iturned open base directories OFF, and php safe mode, ON. and register globals OFF
The site is not being used and is basically a sitting duck waiting to be hacked just for finding out how they do it.
Today, i go and see that anonymopus uploaded a c99.php file to the pafiledb screenshots folder. I thought php was supposed to be blocked by default. I go into my acp and double check the blocked extensions and sure enough php is on there yet I STILl got a php file uploaded to my server that we all know we dont want on our servers. Especially c99.php
So far, this has been the only onen that has got by ctracker and phpbb security so far that I know of. Checked all of my logs and etc, and all is fine elsewhere. This was the only file that was uploaded.
Since I saw this, i have once again set permissions how they should be to only allow admin to upload.
I dont know if anyone else has ever had this happen before. I just wanted to get the word out to you all here.
phpBB Type: Integramod 141
MODs: No
Your knowledge: Basic Knowledge
Board URL: http://mweva.com
PHP Version:
MySQL Version:
What was done before the problem appeared?
Nothing. Basic plain jane install. Only thing different is the sites banner
What was done to try to solve the problem?
Reset permissions for uploads
De.scription and Message
Hello all. a while back my site was hacked and the ONLY mods installed were activity mod and AUCG.
I uploaded a fresh site, on my server, iturned open base directories OFF, and php safe mode, ON. and register globals OFF
The site is not being used and is basically a sitting duck waiting to be hacked just for finding out how they do it.
Today, i go and see that anonymopus uploaded a c99.php file to the pafiledb screenshots folder. I thought php was supposed to be blocked by default. I go into my acp and double check the blocked extensions and sure enough php is on there yet I STILl got a php file uploaded to my server that we all know we dont want on our servers. Especially c99.php
So far, this has been the only onen that has got by ctracker and phpbb security so far that I know of. Checked all of my logs and etc, and all is fine elsewhere. This was the only file that was uploaded.
Since I saw this, i have once again set permissions how they should be to only allow admin to upload.
I dont know if anyone else has ever had this happen before. I just wanted to get the word out to you all here.