[thelist] hacked by yossi and I can't get up

Joel Canfield joel at spinhead.com
Wed Aug 1 10:45:21 CDT 2012


Dunno. Brian has pointed me toward theme hackage, which led me to the
discovery that Thesis 1.7 is hacked, but 1.6 was okay. Downgraded to the
old version, and we'll clean up the new one.

I sure hate "helpful" tools which make simple web dev like doing brain
surgery with winter mittens.

On Wed, Aug 1, 2012 at 10:37 AM, Ron <ronr at linuxdude.com> wrote:

> Just did a quick telnet pembrokeshirepaths.co.uk 80
>
> it shows
>
> Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5 DAV/2
> FrontPage/5.0.2.2635 mod_bwlimited/1.4 mod_auth_passthrough/2.1
> mod_perl/2.0.4 Perl/v5.8.8 Server at cpanel17.uk2.net
>
>
> Isn't that a very old version of Frontpage?
>
> ~
>
>
> On 08/01/2012 11:10 AM, Joel Canfield wrote:
>
>> a friend's site has been hacked and I can't find the hole
>>
>> http://pembrokeshirepaths.co.**uk/ <http://pembrokeshirepaths.co.uk/>
>>
>> looking via ftp, in WordPress, MySQL, I can't figure out where this is
>> coming from. index.php is the usual WordPress file, there's no other index
>> file in the root, database looks normal.
>>
>> ideas?
>>
>>  --
>
> * * Please support the community that supports you.  * *
> http://evolt.org/help_support_**evolt/<http://evolt.org/help_support_evolt/>
>
> For unsubscribe and other options, including the Tip Harvester
> and archives of thelist go to: http://lists.evolt.org
> Workers of the Web, evolt !
>



-- 
Joel D Canfield
Joel at Spinhead.com | http://Spinhead.com/ <http://spinhead.com/>| 916.390.2262
W*e*b D*e*sign for th*e* R*e*al World**
Have you heard about our "Ready, Set, Go!" Instant Blog package?
http://spinhead.com/ready-set-go-instant-blogging-300/


More information about the thelist mailing list