GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Zero Hour ATX/AT3 Hack ***Patch your scripts*** (https://gfy.com/showthread.php?t=695410)

spasmo 01-12-2007 05:59 PM

Zero Hour ATX/AT3 Hack ***Patch your scripts***
 
My apologies if this is a duplicate. I didn't see it on the first page.

If you are running ATX or AT3, please visit http://www.arrowscripts.com/patch.shtml.

Your system is only at risk if your signup forms are enabled.

Spunky 01-12-2007 06:08 PM

Was it similar to the TM3 attack?

spasmo 01-12-2007 06:15 PM

Quote:

Originally Posted by Spunky (Post 11721720)
Was it similar to the TM3 attack?

The only public info I've seen is that you should be on the look out for "strange" new trades that contain exploit code in the email sent to you when the new trades sign up.

MrVids 01-12-2007 06:21 PM

thanks for the heads up
patched mine this morning, should have made a post myself

fris 01-12-2007 06:24 PM

big heads up, hope they notified everyone by email

Spunky 01-12-2007 06:24 PM

Cool..thanks for the info Spasmo

spasmo 01-12-2007 06:27 PM

Quote:

Originally Posted by Fris (Post 11721766)
big heads up, hope they notified everyone by email

They did, in a way. I received notification via email, and though it was from Aheib, it was using the broadcast mailing list from another site you likely frequent.

GrouchyAdmin 01-12-2007 06:55 PM

Not sure if this affects other builds, but I just sent them an email:

Anyone using the CentOS 4 version of AT3 (at least) will see their admin works, but if they go to the settings page, it bitches about a missing file. This is (mostly) ok.

Create an empty file in notepad (or touch on UNIX), named 'informer.dat'. Upload or move to your at3-install/d directory. admin.cgi works again.

I'm betting they left debugging on by mistake; there's no use of 'd/informer.dat' in any previous build of admin.cgi.

spasmo 01-12-2007 07:00 PM

It didn't happen to me on FC4, but he whipped those out in a hurry. He's getting some sleep before doing Mandrake and the others he didn't get to.

Thanks much for the tip. :thumbsup

xApster 01-12-2007 07:56 PM

thank god for http://www.swiftwill.com

abshard 01-12-2007 08:02 PM

Quote:

Originally Posted by toonpornblog (Post 11721918)
Not sure if this affects other builds, but I just sent them an email:

Anyone using the CentOS 4 version of AT3 (at least) will see their admin works, but if they go to the settings page, it bitches about a missing file. This is (mostly) ok.

Create an empty file in notepad (or touch on UNIX), named 'informer.dat'. Upload or move to your at3-install/d directory. admin.cgi works again.

I'm betting they left debugging on by mistake; there's no use of 'd/informer.dat' in any previous build of admin.cgi.

If you upgraded to build 12 of at3 you should have the 'd/informer.dat'

bottom of the page http://www.arrowscripts.com/atl3_dl.shtml

woj 01-12-2007 08:21 PM

Quote:

Originally Posted by xApster (Post 11722298)

:thumbsup

GrouchyAdmin 01-12-2007 08:35 PM

Quote:

Originally Posted by abshard (Post 11722324)
If you upgraded to build 12 of at3 you should have the 'd/informer.dat'

bottom of the page http://www.arrowscripts.com/atl3_dl.shtml

How strange; I checked my upgrade package, and nope, it wasn't in there. Guess I might have grabbed it at a slightly-off build? Who knows. Thanks for the head's up, it IS in this fresh download. Fixed, and reapplied the new CGIs.

com 01-12-2007 11:26 PM

rofl zero hour... sorry guys.. this is comedy


All times are GMT -7. The time now is 08:04 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123