Revcms Exploit Help (PHP)

steno

Member
Feb 18, 2011
56
0
Hello Devbest,

I have just had someone come on my hotel and they claimed to use a PHP exploit to rank themself.

Where is the exploit located in? How do i fix it? and How do i know if it's an exploit?

Please help

Regards,
 

Balls

Member
Jun 1, 2013
251
46
Did they rank themselves or not? You should look into your user database and find the guy and ip block him from your website.
In the mean time, you can look around on the forum for any expolit fixes. Most recent:
 

steno

Member
Feb 18, 2011
56
0
They ranked themselves. And used the hotel alert command. I'm using Revcms and using custom-habbo theme.

I also patched exploits up from that thread you provided.
 

Balls

Member
Jun 1, 2013
251
46
They ranked themselves. And used the hotel alert command. I'm using Revcms and using custom-habbo theme.

I also patched exploits up from that thread you provided.
All I can advise is to change database/vps/hotel login password. IP Block them from the hotel and use a more secure custom theme for the time being.
 

steno

Member
Feb 18, 2011
56
0
Apparently the exploit was in my profile.php and tradesettings.php. I can see on the profile page they may have used the motto field to put a PHP script in there to rank themselves.
 

Users who are viewing this thread

Top