TUCoPS :: Web :: Servers :: websit~1.txt

Website Pro v2.0 allows remotes users to replace files on your website. (Used to break into www.idsoftware.com)


[ http://www.rootshell.com/ ]

Date: Tue, 16 Feb 1999 17:45:09 -0600
From: Christian Antkow <xian@IDSOFTWARE.COM>
Subject: Website Pro v2.0 (NT) Configuration Issues

 As some of you might be aware, our website (www.idsoftware.com) was hacked
this morning using the "out-of-the-box" features of Website Pro 2.0. The
perpetrator used /cgi-dos/args.bat as well as /cgi-win/uploader.exe to
upload new files and overwrite our index.html file with a "Free Kevin"
webpage (identical to the opening page of www.2600.com).

 Any admins out there running Website Pro for NT might want to double check
your security settings, and possibly remove these demo files if you don't
have an explicit need for them to exist.

 Cheers,

 -Xian


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH