View Single Post
  #129  
Old 10-25-2008, 04:05 PM
 
PuroPlacer PuroPlacer is offline
 

Advanced Member
  
Join Date: Jan 2007
Location: Marbella, Spain
Posts: 61
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

God knows, I got the nightwatch guy, he says the following:

Support: i can not rely on any personal opinion as it would be the huge debate, but following method is most dangerous to use exec, passthru, unescape, base64, eval
Support: i can see many methods used on your sites
Support: also php has developed safe_mode - to prevent such issue, but it has been disabled due to the need of the application


He seems to believe that this is a vulnerability in x-cart... Which would also seem most plausible to me.. Although I am not an expert on this stuff..
There were no logins visible from the other server that had been compromised either a couple days ago
__________________
PuroPlacer
X-Cart version
X-Cart Pro 4.1.5
Reply With Quote