Previous Thread
Next Thread
Print Thread
Hop To
Joined: Sep 2006
Posts: 15
D
stranger
stranger
D Offline
Joined: Sep 2006
Posts: 15
I have a 7.3 board up and running for testing. There are no links to it on any web page yet someone was able to upload a bank phishing page to one of the board sub-directories. The installation specifies that some directories be writable to the world (777). Can I change these without compromising the function of the boards? How else can I protect myself?

Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
The only way I know that someone can do that with the permissions set to 777 is that the server it self allows Anonymous log in to the server to the web site. If you have Anonymous users accessing your folders via FTP or Windows Explorer then you need to change your sites FTP settings to not allow any Anonymous logins to the server.

Joined: Jun 2006
Posts: 16,301
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,301
Likes: 116
Yeh, just because a FOLDER is chmodded 777 doesn't mean people can just randomy upload to it...

Likely, some script has been comprimised on your system and they just uploaded their stuff to that directory through the script that they exploited.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Sep 2006
Posts: 15
D
stranger
stranger
D Offline
Joined: Sep 2006
Posts: 15
Anonymous FTP is not enabled. Ubbthreads 6.5 is installed on the same system. Is there a script in 6.5 that can be compromised to upload stuff. I've found four directories with these phishing pages - two in the 6.5 directory hierarchy, one under the 7.3 directory and one outside these directories but in another directory with 777 permissions. All are owned by user apache. The only scripts are in the 6.5 and 7.3 directories, everything else is static HTML files.

Joined: Jun 2006
Posts: 16,301
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,301
Likes: 116
I believe that an early 6.5 build had some security issues; so it could be that; you should at least upgrade to the latest 6.5 build (if not upgrade to UBB.T7)


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Version 7.7.5 Images suddenly not displaying
by Stovebolt - 05/04/2024 11:19 AM
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
Who's Online Now
2 members (ahmed047, Nightcrawler), 558 guests, and 167 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240506)