Website Pro v2.0 (NT) Configuration Issues

From: Christian Antkow (xianat_private)
Date: Tue Feb 16 1999 - 15:45:09 PST

  • Next message: Anthony C . Zboralski: "[HERT] Advisory #002 Buffer overflow in lsof"

     As some of you might be aware, our website (www.idsoftware.com) was hacked
    this morning using the "out-of-the-box" features of Website Pro 2.0. The
    perpetrator used /cgi-dos/args.bat as well as /cgi-win/uploader.exe to
    upload new files and overwrite our index.html file with a "Free Kevin"
    webpage (identical to the opening page of www.2600.com).
    
     Any admins out there running Website Pro for NT might want to double check
    your security settings, and possibly remove these demo files if you don't
    have an explicit need for them to exist.
    
     Cheers,
    
     -Xian
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:35:15 PDT