Forum Moderators: DixonJones

Message Too Old, No Replies

AWStats flaw

My sites just got "defaced"

         

twinsrul

3:16 pm on Mar 7, 2005 (gmt 0)

10+ Year Member



Hey guys using AWStats, hackers got into my site and "defaced" the index page through a flaw in AWStats. Thank goodness just they just changed the index page. Make sure you guys are running AWStats 6.3-r2. I learned the hard way.

More info here: [gentoo.org...]

bcolflesh

3:18 pm on Mar 7, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The bigger lesson is not to place the AWStats files in a publically read/write - able area.

amznVibe

3:46 pm on Mar 7, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



A warning has been posted in at least two threads on WebmasterWorld.
[webmasterworld.com...]
[webmasterworld.com...] <- a month old

twinsrul

10:45 pm on Mar 7, 2005 (gmt 0)

10+ Year Member



bcolflesh, I use a third party hosting company for my websites, I had no control over where awstats was set up.

amznVibe, I notice that you posted in Webmaster General. IMO, your post would of been better if you would of posted your AWStats flaw thread in Tracking and Logging.