PDA

View Full Version : Security Expliot with PHPLiveHelper


Vic - WolfPaw Computers
06-30-06, 09:45 PM
Anyone using PHPLiveHelper on their website - if you recently upgraded from v1.8 to 2.0 - or are running ANY version earlier than 2.0 - contact us offlist for important information to prevent hackers uploading trojan's to your server.

Hosting companies - you may need to scan your servers for IRC Bots uploaded by this expliot. Contact us offlist for file details.

For security purposes, we will not post the explioted filenames or methods. We just want to advise those that are using this product how to secure it.

PHPLiveHelper's development team fixed the expliot in v2.0, however they were not aware of an issue we brought to their attention and are now changing their upgrade instructions to eliminate the issue.

dotCOM-steven
07-03-06, 08:31 PM
Vic,

Good comment and yes, you are very correct.

Users need to get an upgrade or at least change the defualt directory where the software is located.

It's a great time to look at ALL php scripts a user/site owner has. phpBB and a few others have been the focus of injection scripts (hacks) and the fix is easy...keep your PHP scripts updated.

Datagg
07-04-06, 07:39 PM
Anyone using PHPLiveHelper on their website - if you recently upgraded from v1.8 to 2.0 - or are running ANY version earlier than 2.0 - contact us offlist for important information to prevent hackers uploading trojan's to your server.

Hosting companies - you may need to scan your servers for IRC Bots uploaded by this expliot. Contact us offlist for file details.

For security purposes, we will not post the explioted filenames or methods. We just want to advise those that are using this product how to secure it.

PHPLiveHelper's development team fixed the expliot in v2.0, however they were not aware of an issue we brought to their attention and are now changing their upgrade instructions to eliminate the issue.

Good job Vic

Datagg
07-04-06, 07:40 PM
Good Job Vic