Jump to content

Recommended Posts

Posted

Hi Everyone

 

This is the second time my guestbook (advanced GB) has been hacked. I had a current backup of the sql database and restored it and the guestbook is fine now. But what I need to know is how can I stop this from happening on a regular basis. Any ideas are welcome and thanks in advance.

 

Lee

Posted

Bill

 

It is Advanced Guestbook 2.3.1

 

And I had this problem about 3 or 4 months ago and needed to upgrade, and I did.

 

Lee

Posted

I dont want to publish the hack for 2.3.1 but its very easy to do so.

 

This version of Advanced Guestbook has been compromised as well.

 

I sent you the link on the hack via your PM.

 

My only suggestion is to look for another Guestbook with less compromises.

Posted

Thanks Bill

 

Got any GB to look at.

 

Thanks again.

 

Lee

Posted

Question for Don

 

I think I will use Viper Guestbook. My question is this, in the install instructions it says to enter MySQL datas in the install form, what is this data??

 

Thanks for the help. I am not the most upto date person on SQL data bases.

 

Lee

Posted

Thanks Thomas

 

Lee

Posted (edited)

And to clarify (I just learned this! Wow! I get to share!!) the "databasename" that Thomas talked about is a database that you specifically create for this application, following the instructions given in the tutorial link he added to this thread.

 

Don't just type in "databasename" because it won't work. You have to create a database first and then replace "databasename" with the name of the database you created.

Edited by abinidi
Posted

Now if people would actually visit the official forums of the scripts they have problems with they would find that there is a patch to the Advanced Guestbook 2.2 login exploit. The exploit only exists in 2.3.1 where a user has updated from 2.2 and kept the sessions.class.php file from 2.2 to fix a login loop which I have since fixed. Did you lose any entries when they "hacked" your guestbook? I use the term hacked lightly as they are just kiddies that found an exploit published on the net that was so simple they could actually use it.

Posted

Ah, but you see, forums are not the appropriate place to inform people about your software's vulnerabilities. If there's something serious to report, it should be in a page dedicated to it. Perhaps a news page, or advisories page? Maybe even a low volume mailing list people can subscribe to? I don't see any of this on Advanced Guestbook's site, so perhaps you should consider implementing them instead of expecting people to visit the forums to gain knowledge about the latest security flaws of your software :)

Posted

The vulnerability was reported over two years ago when Advanced Guestbook 2.3.1 was released. The exploit exists in 2.2 and 2.3 hence 2.3.1 was released.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...