Jump to content

harmful scripts found by site provider in /.tmp folder


Guest travnape

Recommended Posts

Guest travnape

ok I tried searching the forum but found nothing specific to this. my site provider locked me out because this was found:

root@pro34 [siteroot]/public_html/cubecart/images/uploads/.tmp]# ll

total 739108

d--------- 2 root root 4096 Jan 7 12:32 ./

d--------- 4 root root 4096 Jan 7 12:37 ../

---------- 1 root root 0 Jan 7 03:37 2.Single.a.Nozze.2005.iTALiAN.DvdRip.XviD.RiVoLTs.avi

---------- 1 root root 1503 Jan 6 07:49 c

---------- 1 root root 1 Jan 7 12:35 httpd

---------- 1 root root 20034 Jan 7 12:12 Infodll.log

---------- 1 root root 504 Jan 7 12:32 Infodll.state

---------- 1 root root 504 Jan 7 12:29 Infodll.state~

---------- 1 root root 731967488 Jan 6 07:59 Lady.Henderson.Presenta.2005.iTALiAN.DvDRip.MD.XivD.RiVoLTs.avi

---------- 1 root root 24078928 Jan 5 10:13 Saw.2.2005.italian.md.dvdrip.xvid-SkA.avi

---------- 1 root root 1 Jan 7 12:34 xh

I have no clue how they got here. How do things get uploaded through cube cart by people anyways? please help if you can or send me a thread link that deals with this I didn't have any luck.

Link to comment
Share on other sites

Guest travnape

well do you have the link to this thread otherwise you know the next question.... is there a patch for this loop hole exploit? and without action what is the chance that this can happen again?

I'm using version 3.06 I believe but can't confirm that becasue I don't have access to my web server

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...