View Single Post
  #7  
Old 12-25-2008, 11:20 AM
 
CLPeters CLPeters is offline
 

Newbie
  
Join Date: May 2007
Posts: 5
 

Default Re: Security bulletin 2008-25-12

I reported this vulnerability on the 21st when I found that someone had somehow installed a couple fake Bank of America login pages on my server. I would strongly suggest that all users check their file system just to be safe.

The pages were loaded to my /payment/ directory on my server.

Also... if you don't need it to be on "allow_url_fopen" in your php.ini should be off as that will stop them from running the scripts from other servers.
__________________
Version 4.1.11
Reply With Quote