Security Alert Check from Pagesetter  Bottom

  • I've just gotten a few of these emailed to me from my guild site and I just don't know enough about Pagesetter to know if it's potentially harmful, though I can't see this entry doing anything.

    Could I please get a knowledgeable opinion?

    Code

    Attention site admin of The Dominion of  Heroes,
    On Mar 22, 2008 at 01:49 PM the PostNuke code has
    detected that somebody tried to send information
    to your site that may have been intended as a
    hack. do not panic, it may be harmless: maybe this
    detection was triggered by something you did!
    Anyway, it was detected and blocked.
    The suspicious activity was recognized in
    pnAntiCracker on line 55, and is of the type
    pnSecurity Alert.
    Additional information given by the code which
    detected this: GET Intrusion detection.

    Below you will find a lot of information obtained
    about this attempt, that may help you to find
    what happened and maybe who did it.


    =====================================

    Information about this user:
    =====================================
    This person is not logged in.
    IP numbers: [note: when you are dealing with a
    real cracker these IP numbers might not be from
    the actual computer he is working on]
         IP according to HTTP_CLIENT_IP:
         IP according to REMOTE_ADDR: 87.230.7.194
         IP according to
    gethostbyname($_SERVER['REMOTE_ADDR']):
    87.230.7.194


    =====================================
    Browser information
    =====================================
    HTTP_USER_AGENT: Mozilla/5.0 (Macintosh; U; PPC
    Mac OS X Mach-O; en-GB; rv:1.7.10) Gecko/20050717
    Firefox/1.0.6
    BROWSER * 0 :

    =====================================

    Information in the $_GET array
    This is about variables that may have been in the
    URL string or in a 'GET' type form.
    =====================================
    GET * module : Pagesetter
    GET * amp;func : viewpub
    GET * amp;tid : 1
    GET * amp;pid : 6\"[removed injection code]

    =====================================
    Information in the $_POST array
    This is about visible and invisible form elements.
    =====================================

    =====================================
    Information in the $_COOKIE array
    =====================================

    =====================================
    Information in the $_FILES array
    =====================================

    =====================================
    Information in the $_SESSION array
    This is session info. The variables
      starting with PNSV are PostNukeSessionVariables.
    =====================================
    SESSION * PNSVlang : eng




    edited by: Topiatic, Mar 23, 2008 - 09:36 AM

    --
    Under Construction!
  • it looks like an attempt of a 'blind' remote code injection (not related to postnuke itself) - don't worry about it (as long as there is no /addons/guildbank/searcharrays.php somewhere on your webspace...)

    --
    regards from germany
    ..::[Zikula Application Framework]::.. ..::[SEO-Blog]::.. ..::[CMS Sicherheit]::..
  • larsneo

    it looks like an attempt of a 'blind' remote code injection (not related to postnuke itself) - don't worry about it (as long as there is no /addons/guildbank/searcharrays.php somewhere on your webspace...)


    Thanks! And no it doesn't exist in my directories... but I discovered it does in WoWRoster for DragonFly...

    --
    Under Construction!
  • Quote

    but I discovered it does in WoWRoster for DragonFly...

    yepp - and there might be a remote code injection exploit icon_rolleyes

    --
    regards from germany
    ..::[Zikula Application Framework]::.. ..::[SEO-Blog]::.. ..::[CMS Sicherheit]::..
  • I did have the decency to contact them and inform them of the attempt along with the relevant info... and am going to delete the critical part out of my OP (hadn't thought about that one icon_eek ).

    --
    Under Construction!

This list is based on users active over the last 60 minutes.