You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 

Author: Evaders99PostPosted: Thu Mar 26, 2009 7:34 pm    Post subject:

What version are you using? No current phpNuke uses pm.php

Author: R5-T2PostPosted: Thu Mar 26, 2009 9:05 pm    Post subject:

7.8

Author: Evaders99PostPosted: Thu Mar 26, 2009 11:33 pm    Post subject:

Have an example? I don't see this in my files anywhere

Author: R5-T2PostPosted: Thu Mar 26, 2009 11:57 pm    Post subject:

It was sitting in the /html directory.

Typing MYWEBSITE.com/pm.php would show the entire history.

I moved it. Everything still works.

Author: Evaders99PostPosted: Fri Mar 27, 2009 6:02 pm    Post subject:

Good enough. This file isn't included anywhere in the phpNuke package Wink

Author: SlackervaaraPostPosted: Fri Mar 27, 2009 9:01 pm    Post subject:

I would guess that a hacker has uploaded pm.php to your site. Similar things happened to me when I used SpChat. Certain modules can be abused to upload things.

Author: R5-T2PostPosted: Sat Mar 28, 2009 8:19 am    Post subject:

Could be. One thing is certain. It was put there intentionally by someone.

Author: moshxsoftPostPosted: Wed Sep 16, 2009 7:02 am    Post subject:

What version are you using?

Author: kbgusPostPosted: Thu Sep 24, 2009 6:58 pm    Post subject:

I know this is a little late, but for future reference:

Check with your web host - this looks like a server security issue. Also check your web logs.

Author: SlackervaaraPostPosted: Thu Sep 24, 2009 9:18 pm    Post subject:

When you look in your accesslogs make a search in them for pm.php and you will maybe easy find how the hacker uploaded it.



Nuke Cops -> Installation for Newbies

All times are GMT - 8 Hours

Page 1 of 1

Powered by phpBB © 2001,2002 phpBB Group
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 191 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - pm.php direct access?!? pm.php direct access?!?

Nuke Cops -> Installation for Newbies

Author: R5-T2 PostPosted: Thu Mar 26, 2009 12:53 pm    Post subject: pm.php direct access?!?

I noticed every PM ever sent on our site is easily viewed by typing the pm.php directory location in a web browser. No registration is necessary.

Surely this is not supposed to work this way.
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.096 Seconds - 193 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
added by Evaders - DO NOT REMOVE
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::