Go to the FreeLists Home Page Home Signup Help Login
 



[dokuwiki] || [Date Prev] [02-2008 Date Index] [Date Next] || [Thread Prev] [02-2008 Thread Index] [Thread Next]

[dokuwiki] Re: attempt to use possible vulnerability of dokuwiki

  • From: Jonathan Dill <jonathan@xxxxxxxxx>
  • To: Todd Augsburger <todd@xxxxxxxxxxxxxxxx>
  • Date: Mon, 11 Feb 2008 16:16:24 -0500
Todd Augsburger wrote:
Interesting stuff! (Although only marginally about DokuWiki)

Googling "namogofer" or its md5('f') response gets hundreds of hits, so I assume there are a significant number of compromised hosts. Any idea what the target app was?
Certain versions of Word Press seem to be a popular target, but it looks like it could potentially affect any PHP script without adequate input validation on a server with url_fopen enabled. Someone also pointed me to this page, which has some fixes that you can use on shared hosting where you don't have access to the system php.ini.

http://www.embedded.ch/http.htm

Jonathan
--
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist




[ Home | Signup | Help | Login | Archives | Lists ]

All trademarks and copyrights within the FreeLists archives are owned by their respective owners.
Everything else ©2007 Avenir Technologies, LLC.