project rafs exploit found

Live forum: http://forum.freeipodguide.com/viewtopic.php?t=30840

igneous

18-01-2006 20:44:54

A user on another site found an exploit in project rafs, and lets just say its not too good for those of you who run sites with that script. I cant post how to do it, but theres a way to get into the admin panel very easily.

dudelovesFinch1035

18-01-2006 20:48:49

Who's the user?

Daggoth

18-01-2006 20:49:37

I'd let Orderit4Free, GetNFriends, and AnyGift know immediately.

mr_black

18-01-2006 21:07:11

there are so many exploits in the script i know how to completely destroy a site in 1 simple step.

MegaFreebie

18-01-2006 21:15:25

We are very interested in any information that anybody has. We are trying to do everything in our power to keep our site from being hit short of taking the site down.

igneous

18-01-2006 21:27:44

I PMed you.

theysayjump

18-01-2006 21:34:56

Yeah please let every site owner who uses this know.

Admin

18-01-2006 21:50:16

hate to say i told you so...

MegaFreebie

18-01-2006 22:02:31

Everybody knows RAFS isn't the most secure. I believe we have taken care of this exploit for now.

shamash

19-01-2006 07:13:27

The only thing you need to do is add a .hpasswdurl==http://=http:///url to the /admin/ folder... If you didn't have that already, your site wasn't very secure anyways.

mr_black

20-01-2006 08:55:18

http//freegiftsubscriptions.com/ hax0rd lishakes headli

dudelovesFinch1035

20-01-2006 08:57:42

OMG

johnjimjones

20-01-2006 09:07:02

[quote61a17abe2a="mr_black"]http//freegiftsubscriptions.com/ hax0rd lishakes headli[/quote61a17abe2a]
ahh the gay porn hack

mr_black

20-01-2006 09:12:21

[quoteec3fbf7b01="johnjimjones"][quoteec3fbf7b01="mr_black"]http//freegiftsubscriptions.com/ hax0rd lishakes headli[/quoteec3fbf7b01]
ahh the gay porn hack[/quoteec3fbf7b01]

i allmost chucked when i saw this liWARNING DO NOT LOOK IF U HAVE A WEAK STOMATCH ~seriously!~li http//www.gascards4you.com

whoever is doing this....should be choked

johnjimjones

20-01-2006 09:21:09

[quote7705f527dd="mr_black"][quote7705f527dd="johnjimjones"][quote7705f527dd="mr_black"]http//freegiftsubscriptions.com/ hax0rd lishakes headli[/quote7705f527dd]
ahh the gay porn hack[/quote7705f527dd]

i allmost chucked when i saw this liWARNING DO NOT LOOK IF U HAVE A WEAK STOMATCH ~seriously!~li http//www.gascards4you.com

whoever is doing this....should be choked[/quote7705f527dd]
awwwwwwwww i click the link x shock ? cry

Wolfeman

20-01-2006 10:34:44

LOL, tubgirl. My favorite part is how they blur out har vag. Like thats the offensive part... No goatse yet?

tracemhunter

20-01-2006 11:08:39

4freezone got hacked as well.

EatChex89

20-01-2006 11:11:26

[quotec9b29ac65e="tracemhunter"]4freezone got hacked as well.[/quotec9b29ac65e]

how? everything looks the same

tracemhunter

20-01-2006 11:11:59

well i got an email from them saying they did. the email was carbon copied and it said that everything from some date got deleted and they were trying to fix it all. i deleted it though...