Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

official guestbook hacked?

Asked Modified Viewed 11,072 times
W
Wanabo
W
Wanabo 10
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
  • Senior Member, joined since
  • Contributed 598 posts on the community forums.
  • Started 94 threads in the forums
  • Started this discussions
asked
Senior Member

Found this guestbook entry in 3 of 5 sites I own.

All sites are in the Dutch language, but the guestbook entry is English submitted by a Polish person.

I regard these entries as spam.

Left 1 example in my guestbook for you to see! --> guestbook example <-- Edit: example removed, but feel free to take a look at my Dutch guestbook! ;)

It's the entry by Tomek.

If these entries are manual then there is no problem.
If these entries are automated, additional protection is needed.
Edited by Wanabo on 29-09-2006 17:10,
0 replies

8 posts

S
Sbhedges
S
  • Member, joined since
  • Contributed 145 posts on the community forums.
  • Started 7 threads in the forums
answered
Member

oh.....I don't regard it as Spam but since its your site. I don't know if its automated, I think it looks manual though. To check change the folder in infusions called guestbook to something then change the main file guestbook.php to same as the folder, You might want to edit guestbook.php to link it up
0 replies
W
WEC
W
WEC 10
  • Veteran Member, joined since
  • Contributed 946 posts on the community forums.
  • Started 5 threads in the forums
answered
Veteran Member

Thre are some older MODS to protect guestbook. Don't know if they will still work but you could check that:

http://www.phpfusion-mods.com/forum/v...8&pid=6351
0 replies
G
gojuryu
G
www.gojuryu.net
Online since 1998 & running PHP-Fusion since 2004
  • Member, joined since
  • Contributed 105 posts on the community forums.
  • Started 16 threads in the forums
answered
Member

I'm sure that is automated as it is the same message and link I have seen maybe 50 times over the last year.
0 replies
W
Wanabo
W
Wanabo 10
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
  • Senior Member, joined since
  • Contributed 598 posts on the community forums.
  • Started 94 threads in the forums
  • Started this discussions
answered
Senior Member

Well no more "spam" messages occur! So I guess there is no real spam danger, otherwise all php-fusion sites would have been flooded by now.

I remove mentioned guestbook entry! And edit the first post.
0 replies
B
braajeri
B
  • Member, joined since
  • Contributed 68 posts on the community forums.
  • Started 1 thread in the forums
answered
Member

Ummm, since this was an issue of spamming - not hacking - was it necessary to use the word "hacked"? in the subject line? We've already had some folks (falsely) accusing PF of being responsible for hacks in the last few weeks so this is not the best subject line to use in this instance.

Guestbooks that don't have some sort of spam protection are an issue on ANY site, inside a CMS or not.
0 replies
W
Wanabo
W
Wanabo 10
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
  • Senior Member, joined since
  • Contributed 598 posts on the community forums.
  • Started 94 threads in the forums
  • Started this discussions
answered
Senior Member

@braajeri
Wel if a weakness or security hole is exploited I call it a hack. In this case I thought it was the guestbook. And please take a note on the questionmark! in the subject line.

I know to what post you're referring when you're talking of some folks.. and you really upset me when you compare me with them.
0 replies
E
enablingwolf
E
  • Junior Member, joined since
  • Contributed 14 posts on the community forums.
  • Started 2 threads in the forums
answered
Junior Member

tomek has been in my guest book also. I assume he is getting addresses from the support sites for Fusion. It is part of the web, and dealt with the nice tools of blacklisting him and his crowd. :D



Here is his WHOIS info:


http://whois.domaintools.com/212.122....22.215.107

He has a nice range of IP's:

212.122.215.0 - 212.122.215.255



Looking at some info in light of strange entries, his site (IP) is listed as SPAM on SORBS.

So he gets a nice blacklist on my site.
0 replies
B
braajeri
B
  • Member, joined since
  • Contributed 68 posts on the community forums.
  • Started 1 thread in the forums
answered
Member

@Wanabo, not comparing you to any other poster. Just saying we need to all think before using the word "hacked" in the subject line if the issue is just spam and not hacking. I remember some time back that I never even paid attention to the guestbook in PF until I looked at some stats for my site. Most of the hits were for guestbook.php. I havd literally 100s of entries, 99.99% of which were total spam. Is that an exploit? No, the guestbook is just a simple form that bots can utilize to enter spam. So I just went in phpmyadmin and wiped out all of the entries and disabled the guestbook. If you want to keep your guestbook open (who uses guestbooks anymore besides spammers?), install one of the spam protection mods.
0 replies

Category Forum

Bugs and Errors - 6

Labels

None yet

Statistics

  • Views 0 views
  • Posts 8 posts
  • Votes 0 votes
  • Topic users 6 members

0 participants

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet