Master-X
|
| |
 »  » CJs » 
: Smart-Thumbs ?
   

26/09/07 17:42
 X-dream
<!--#include virtual="/st/db_structure.php"-->

db_structure.php 15 .

? )

: X-dream (01/10/07 20:55), 3 ()

26/09/07 17:44
 usanatol
icon_smile.gif

26/09/07 17:47
 X-dream
:
Zend 2003120701 1 2326 8227 x
2 Zˏ: x S/=(F6 9m9j+G֦NT %JK["e}\cs-^zCڢ)ھtaQ&#152;#?5Qm@T?_4uM *1/
f
}4r葧g8 cn;iM~
T(ț1w`Ó
loLCcc)@STY}؜\
iHEI4#3לb*}T(AUA^}bDuA`EޝZSzL&#152;1!U='z0ZU MUk,V$ e&c
PF@C@tpj/
Qj2TdϞR:jxue]ꖄG˽ .9yӯx2r Gᇵ+qux"/IHOv/%QЯҽ{c2cs>y0c?B1º_uEY=׹*CT$ww ]
ʥQs>w{?\e\e.2{UbGh t(A zQqg̡ \e> a`1{T*A՛2pvv:|ƛ2u|7l$'vڻN&#152;MW$W D(D(L9)̺
{C^4P](Bx,ԚԷ|ȏ!\>% "'6NL`;܅jBx2)YPnrx4e &#152;i1;* HaG;m .R5fJQ5U5ff8rߗU,T,fˊ
wUvZ
UAKbOR^(LE9-ji
PZa0jdKbi\4&vXRV,M2<I^ P YR(
_ɓfEGJE5E2 4IR/Y~Q7뢣e͋b
p" 'L lmrK ?w f K9=$}?8u…>/UP䳵0GX 8DtA^}z{n=O޼{f8%&#152;-y WG嫯dQqCm% u~Wko pk- ~/N1!x<@\+ }v_" K
ݗ,<,}yݗls~e.D'\0ޙd{ GX4HKi ,
޵-ױ7+pmǸAtFevpû_]#0U0~W"-5%4$""sLxƁ1ت
q\$ m9kԮWםl6'tا4MjO9jӋS3ڏV\ݙ.ng½&#152;\sqӲ-zA/Ůo>]#jOkVRcm?6iV%z
(~% g&>HVuZPhBfӅQI>qd+q7 Cw'¥
}J4Ņs~Nlc荹34wZb j#jBsݩs1-GNh9xI}b$^Z_lS|u|5ߪuռHT}pؿ:5l9B-χQ-<2pjoT䀅?8 M13
I̪!.M l4%hJ0h
S os JGQ Nm&#152;H棶9OMO'J䵈j\v
iԣyЂT$kHI4,ܽp03b}L\M7Wk W@L.`-rd ($Qigޱ{7VN`TIɔ$򪌔 _1`ɈݎPȟ? f;H f,= ~a.e'diԐ<<JY+A,1] ^: $ZH PZ3{)YFYl,#Ջ,-
~ kLc#lsG2kP9w9w;Mr"$g1Mf7;+$BG`Q"#RF\QIHP()2_Cǜe޹' ϒʋ6'K5$ }"Ì:
E Ϟ­_Ld&#152;o?' &#152;,?@w1M$z}Mu"IX(:uRMKPu A"m>

26/09/07 17:56
 usanatol
???
... -

26/09/07 18:03
 X-dream


5.68 .

26/09/07 18:07
 shamit
..

26/09/07 18:44
 Diablo
st/admin/rotator.php?action=tools&action_submenu=filecheck&domain_id=1

=)

26/09/07 18:48
 Diablo
,
.
gallery.php - =\ 15 - .

gallery.php - unknown file

:
<?
$g = getenv ("QUERY_STRING");
?>
<html>
<head>
<title></title>
<!-- frames -->
<frameset  rows="100,*">
    <frame name="" src="top.html" marginwidth="10" marginheight="10" scrolling="auto" frameborder="0">
    <frame name="" src="<?php echo $g; ?>" marginwidth="10" marginheight="10" scrolling="auto" frameborder="0">
</frameset>

</head>
</body>
</html>



26/09/07 18:52
 Diablo
%)

if you do not use "st/gallery.php" file to open galleries in frame, delete this file (we removed it from ST because of frequently abuse of this file as place for malicious code - "tools>filecheck" can't check content of this file)

=)

26/09/07 19:40
 Danilax
gallery.php ,

"# if you do not use "st/admin/galery.php" file to open galleries in frame, delete this file (we removed it from ST because of frequently abuse of this file as place for malicious code - "tools>filecheck" can't check content of this file)"

X-dream

?

2. Check admin login/pass under settings>users and remove unknown admin users. If you have access over phpmyadmin, you can display all users from database by running "SELECT * FROM st_users;" query and delete unknown entries from there (because some entries may not be visible from st admin)
3. Check st/admin/.htpasswd file for logins which are unknown for you
4. Check for suspicious files over tools>file check and remove them.
5. Change FTP/SSH and MYSQL logins for all databases on attacked server
6. Enhance your security by following these instructions these instructions
http://www.thumbsrotator.com/help/manual.php?action=help&cmd=help_list&value[pid]=149

01/10/07 20:56
 X-dream
<!--# ="//_."-->

... icon_smile.gif ... ... ... .