Strict Standards: Non-static method serendipity_plugin_api::generate_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_smarty.inc.php on line 611 Strict Standards: Non-static method serendipity_plugin_api::enum_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 847 Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 860 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::load_plugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 872 Strict Standards: Non-static method serendipity_plugin_api::probePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 571 Strict Standards: Non-static method serendipity_plugin_api::getClassByInstanceID() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 521 Strict Standards: Non-static method serendipity_plugin_api::includePlugin() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 526 Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 902 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Only variables should be assigned by reference in /var/www/freebsd.munk.me.uk/include/functions_smarty.inc.php on line 73 Google the SiteQuicksearchStrict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_internal.inc.php on line 408 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 CategoriesHandy LinksStrict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_internal.inc.php on line 1429 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 MRTG Stats Photo Gallery Forums My Amazon Wish List Radio Times My Weather Creative CommonsStrict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/plugins/serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php on line 47 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 FreeBSD WebringStrict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_internal.inc.php on line 1429 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically, assuming $this from incompatible context in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041
Blog Administration |
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_smarty.inc.php on line 553 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Thursday, August 26. 2004Attempts To Exploit My_ eGallery Vulnerability Target Random SitesComments
Display comments as
(Linear | Threaded)
Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_comments.inc.php on line 293 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_comments.inc.php on line 391 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_comments.inc.php on line 391 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Non-static method serendipity_plugin_api::hook_event() should not be called statically in /var/www/freebsd.munk.me.uk/include/functions_comments.inc.php on line 391 Strict Standards: Non-static method serendipity_plugin_api::get_event_plugins() should not be called statically in /var/www/freebsd.munk.me.uk/include/plugin_api.inc.php on line 1041 Strict Standards: Only variables should be assigned by reference in /var/www/freebsd.munk.me.uk/include/functions_smarty.inc.php on line 73
Interesting read.
Php-nuke and postnuke have always been known for their XSS vulnerabilities, I always advice people not to use nuke for any critical purpose unless they know what exactly they are doing and know how to secure nuke.
~rantmode:
I just find it incredibly annoying that these morons seem to be attempting to exploit a hole based solely on the fact that the words 'My_ Egallery' appear anywhere on a website. Since I mentioned the vulnerability in this article, hits have been turning up in the access log for: http://jez.hancock-family.com/modules/My _eGallery/public/displayCategory.php with the payload/xss in a POST request. Given this it seems these script kiddies have a script knocked up that searches for instances of my _egallery anywhere on a site and if they find one they attempt the exploit on the site. Annoying. End rant!!!
Para impedir el ataque:
$bug = strpos($basepath,"http"); $bug2 = strpos($adminpath,"http"); if ($bug == false AND $bug2 == false) { include ("modules/My"."_eGallery/public/imageFunctions.php"); include ("admin/modules/gallery/fileFunctions.php"); |
||||
Strict Standards: Only variables should be assigned by reference in /var/www/freebsd.munk.me.uk/include/functions_smarty.inc.php on line 73