[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-www
Subject:    KDE wiki defaced
From:       Christian Mueller <cmueller () gmx ! de>
Date:       2007-10-11 14:16:26
Message-ID: 200710111616.27306.cmueller () gmx ! de
[Download RAW message or body]

[Attachment #2 (multipart/signed)]


Hello luci, 

the Tikiwiki at wiki.kde.org has been taken over by a cracker.  :-(

Probably via the critical security hole in Tikiwiki that's just been reported: 
http://www.heise.de/security/news/meldung/97259 (in German)
http://milw0rm.com/
http://milw0rm.com/exploits/4509

I suggest disabling tiki-graph_formula.php.
The security hole allows arbitrary PHP code injection 
so I guess the server needs a closer check. 


Cheers,
Christian.


["signature.asc" (application/pgp-signature)]

_______________________________________________
kde-www mailing list
kde-www@kde.org
https://mail.kde.org/mailman/listinfo/kde-www


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic