|
|
|
|
![]() ![]() |
Feb 28 2008, 02:33 AM
Post
#11
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 278 Joined: 25-November 07 From: a beach, in California Member No.: 53,718 |
Ack!!! This comes too late for me. One of my sites was hacked by someone who boasted himself as a hacker. Deleted all my articles and completely wiped all categories. However, I had my backup made and was able to recover...but still My site was "lost content" from Feb 23 ~ Feb 27. A simple rule of making CuteNews to manage only partially may have saved me from whole lot of trouble. That just goes to show me--not one thing should be the complete content management for a site. I had 1/3 in CuteNews, 1/3 custom script and 1/3 plain HTML. wow, so it is true.. i dont see how hackers choose what sites to completely destroy.. pathetic i think.. i mean your a trap17 administrator right???! ah.. please anyone whos reading tell me its not true, that the guy who started the Cutenews Project, completely abandoned it?! also i tried my lilcomments or whatever, and the demo was down, unfortunately if cutenews was abandoned by the owner, i hope someone takes over |
|
|
|
Feb 28 2008, 02:42 AM
Post
#12
|
|
|
Desperately seeking "any key" to continue... ![]() Group: Admin Posts: 3,489 Joined: 23-April 05 From: Trap17 storage box Member No.: 6,042 |
if cutenews was abandoned by the owner, i hope someone takes over CuteNews, like any other scripts, are vulnerable when people are developing it from the ground up. That's why people pay to have scripts that are thoroughly tested. But even with paid scripts there's a constant updates and patches to be on the look out. CuteNews have released the security measurement but I failed to check it on time. This forum, IP.Board, has alert notice section when a new or patch is available. Perhaps it's time for CuteNews to implement something similar. The fault might have been on CuteNews for leaving such hacking potential but that fault is also shared by me not checking CuteNews' support forum on a regular basis. And some clever guy just knowing how to manipulate this vulnerability has nothing to do with my position here at Trap17 |
|
|
|
Feb 28 2008, 08:03 AM
Post
#13
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 344 Joined: 28-July 06 Member No.: 27,449 |
I will still be using cutenews. I will make sure to make login details for cutenews different than cpanel though, don't want them accessing the whole site now, do we? I don't really mind if they wipe the news, I can always just backup, and it is not 100% chance that it'l happen to me.
|
|
|
|
Feb 28 2008, 03:15 PM
Post
#14
|
|
|
Desperately seeking "any key" to continue... ![]() Group: Admin Posts: 3,489 Joined: 23-April 05 From: Trap17 storage box Member No.: 6,042 |
lemonwonder,
If you're not using SEARCH within your CuteNews, just delete the file. Otherwise go to CuteNew's support forum and edit the search.php file to countermeasure the security hole. |
|
|
|
Feb 28 2008, 07:49 PM
Post
#15
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 344 Joined: 28-July 06 Member No.: 27,449 |
Okay. I do not know whether cutenews search will be / is used so ill fix it. Thanks BuffaloHELP
|
|
|
|
![]() ![]() |
Similar Topics
|
Lo-Fi Version | Time is now: 12th October 2008 - 03:38 AM |