Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: InfoSec Handlers Diary Blog InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

phpBB <= 2.0.17 exploit code in the wild

Published: 2005-12-25
Last Updated: 2005-12-25 00:45:05 UTC
by Kevin Liston (Version: 1)
0 comment(s)
It's an early holiday gift for phpBB admins all over the world.  Exploit code affecting phpBB version 2.0.17 and previous has been made public.  The targeted vulnerability was announced on Halloween, and updates have been available since then.

I predict we'll be seeing profile.php probes appear in your web logs right along with the awstats and xml-rpc attacks that you've been getting.
Keywords:
0 comment(s)
Diary Archives