XHP CMS - eXpandable Home Page
Google
Web xhp.targetit.ro


[Archives] [RSS] [Atom]


XHP exploit in the wild

Bad news... it seems we have some attention.

I have reports of an XHP exploit in the wild. I will detail below so you can protect yourselft.

The exploit is actually using a hole in the HTMLArea Filemanager plugin to write malicious files in the /filemanager directory. They first search Google for "Powered by XHP CMS" (consider removing that) to spot victims.

Then they attack HTMLArea (which is included in XHP > v0.4), upload malicious files to the disk and use them to execute whatever the apache user has the right to execute.

You can see that you were attacked if you find in your /filemanager folder files like suntzu*.php.

Quick fix:

1. Remove the directory inc/htmlarea

2. Remove all files in the /filemanager directory (if you think you can see what are the malicious files and what are the files uploaded by you can delete only bad files).

This will of course leave XHP crippled. We are working on a new release to fix this issue. We expect to have it ready this week-end.


Posted Thursday 23rd 2006f March 2006 12:00:08 EET
Modified Thursday 23rd 2006f March 2006 23:51:27 EET


Powered by XHP CMS v0.5.1
Site engine is copyright © 2003-2006 Laurentiu Matei

Produse naturiste | Librarie online | Stock screening