PDA

View Full Version : Possible Security Issue


petero
6th of June 2006 (Tue), 23:15
My account with Acenet in US has just been suspended for sending in access of 200 e-mails per hour. Needless to say, it wasn't me... They suggest that someone is exploiting unsecure php script in my directories. Part of their message to me:
----------------------
If any PHP scripts employed in your account are insecure, then they can be exploited and mail injection may take place where the malicious party exploits your insecure script and sends mail (usually spam) via your script and thus from your domain.
---------------------

Not sure if this may be related to the security issue in another thread, but in my case it results in a major spam action. Any suggestions? (I am running current version of software 1.5 RC4
Peter

MikeCaine
7th of June 2006 (Wed), 03:28
I think it's fairly safe to assume that it's related to the recent hack

You need to clear out any files in your gallery that aren't yours, some may be hidden, some may have the wrong permissions so that you can't delete them yourself.

I've wiped the whole galley and am doing a fresh installation and patching the hole as per http://photography-on-the.net/forum/showthread.php?t=177875

It's a great pity having to do it all over again, especially when version 2 is due (overdue) and day now