VOGONS


www.glidos.net

Topic actions

First post, by ableeker

User metadata
Rank Newbie
Rank
Newbie

Anybody see this?

Reply 1 of 9, by ChaosFish

User metadata
Rank Member
Rank
Member

Oh crap 😒
Lamers. Yes I see that page too.

Reply 2 of 9, by Gambit37

User metadata
Rank Oldbie
Rank
Oldbie

Damn. Nuts.

I thought it only affected sites running phpBB, but it turns out it's also a problem for unpatched versions of PHP. See here:

http://it.slashdot.org/it/04/12/21/2135235.sh … tid=217&tid=169

and here:

http://securityresponse.symantec.com/avcenter … perl.santy.html

Paul, I hope you keep a local backup... 🙁

Reply 3 of 9, by ChaosFish

User metadata
Rank Member
Rank
Member
Gambit37 wrote:

Paul, I hope you keep a local backup... 🙁

I think he does. The backup even comes with the software (when you download Glidos you also download it's website)

Reply 4 of 9, by ableeker

User metadata
Rank Newbie
Rank
Newbie

Did anybody hear from Paul?

Paul, I haven't had time to look into this, but I understand you have to upgrade to phpBB version 2.0.11. Does anybody know if this is correct? Will this do the trick? I think they've also used an exploit in PHP itself, so maybe PHP must also be updated to the newest version? Probably wise to do both, anyway...

Paul did you lose any stuff? Just let us know if there's anything we can help you with!

Funnily enough the unlock service can still be reached by going to http://unlock.glidos.net/unlock.php. Lucky for me, as I needed a couple of new unlock codes. I don't know, it might prove useful to others as well.

Aldo Bleeker

Reply 5 of 9, by Gambit37

User metadata
Rank Oldbie
Rank
Oldbie

See the Slashdot conversation link I posted above for more info and speculation.

Paul doesn't use phpBB on his site, so it must be the PHP vulnerability.

Reply 6 of 9, by Snover

User metadata
Rank l33t++
Rank
l33t++

Slashdot: 503 Service Unavailable
*gasp* Was Kapersky right? Are we in the midst of a cyberterrorist attack?! I NEED MY SLASHDOT AAAAAHHHHHHHHH~!!!!#!$%!#$

Yes, it’s my fault.

Reply 7 of 9, by ableeker

User metadata
Rank Newbie
Rank
Newbie

Take a deep breath, Snover! Calm down! I had no problem getting to Slashdot just minutes ago. I think the're experiencing some problems, but when you wait, you probably will get through. (Maybe Slashdot has been slashdotted?)

Somehow I'm reminded of a scene in one of the Airplane movies, where the crew is explaining to the passengers they're experiencing a number of problems, and even malfunctions. Luckily the passengers take all this extremely well. They then conclude their announcement with the offhand remark that unfortunately there will be no coffee available during the trip, and panic ensues!

Reply 8 of 9, by Snover

User metadata
Rank l33t++
Rank
l33t++

If the host isn't properly locked down, ALL virtual hosted sites on a server are defaced, not just the ones owned by the original user.

Reply 9 of 9, by Glidos

User metadata
Rank l33t
Rank
l33t

It was bloody portland.co.uk, where I host most of the site. They keep getting hacked. http://unlock.glidos.net, served from my machine was fine.