
I'm running the following:
Linux
Apache version 1.3.37
PHP version 4.4.6
MySQL version 4.1.22-standard
My temp folder is chmod 777, so is cache and templates_c
Any help would be appreciated.
Thanks,
David
That feels like someone got console or similar access given nobody/nobody was chmod'd rather than using the user/group of the web server process. How good is your server ? - Try this...stick webadmin.php onto your server and see if you can wander up out of your web space to other parts of the server - if so then others can too). They just used your tmp area as handy disk space rather than an exploit via CMSMS and the fact that it's happened twice means that the original hole isn't closed and the same hacker just happens to remember your pathname (I doubt it's personalscreamingfingers wrote:Anybody know how I can protect my tmp folder? It's been hacked twice. I was using 1.0.4 and I got hacked. Now I'm using 1.1.1 and I got hacked again. CMSMade Simple does not seem to be all that secure to me.
I'm running the following:
Linux
Apache version 1.3.37
PHP version 4.4.6
MySQL version 4.1.22-standard
My temp folder is chmod 777, so is cache and templates_c
Any help would be appreciated.
Thanks,
David