![]() |
|
|||||||
| Chit Chat Public Talk about any thing you want! This forum is public. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
AWStats - Vulnerability?
Has anyone seen the eWeek article (http://www.eweek.com/article2/0,1759,1763152,00.asp) about howthe PhpBB.com website was compromised using a flaw in AWStats? We are on 6.1 I believe. Is there any plan to upgrade?
__________________
Mark |
|
#2
|
||||
|
||||
|
Yea we know about it.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#3
|
|||||||||||
|
|||||||||||
|
It's only an issue if you have Allow Manual Update enabled.
|
|
#4
|
||||
|
||||
|
Well we did update AWstats on all windows servers they are all 6.3 now.
![]() Unix will take a bit of time to update as it does a awstats.pl in every user dir. Brangwyn did I miss something? What is "Allow Manual Update" I thought it was all AWstats and was in the awstats.pl file that caused the issue from what I read on psofts forum anyway.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#5
|
|||||||||||
|
|||||||||||
|
Straight from the AWStats site
Quote:
For those interested it was actually this AWStats exploit that I believe took down the PHPBB2 Home pages... edit this was already pointed out, should have reread the first post myself ![]() Last edited by Brangwyn : 02-10-2005 at 08:02 PM. |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| No AWSTATS from 6/29-7/01 | jmbeach | Chit Chat Public | 1 | 07-05-2004 05:40 PM |
| mnoGoSearch vulnerability | cardmagic | Chit Chat Public | 0 | 07-27-2003 05:45 AM |