Skip to main content Help Control Panel

 

English «   Bug tracker «  

SECURITY ALERT [Integrated]

Bernard Paques -- on Mar. 20 2007, from nearby-an-airport
YACS Leader

Please remove script links/trackback.php manually from your server

WorkflowSupport request
StatusSolution has been fully integrated
  • Submission on Mar. 20 2007 by Bernard
  • Qualification on Mar. 20 2007 by Bernard
  • Finalization on Mar. 20 2007 by Bernard
OwnerBernard Paques
Progress100%
We have been reported one site running YACS 7.2 hacked. The root case analysis has shown repeated attacks on the aforementioned script. Flaws identified here have been fixed in the archive 7.3alpha19 released on March-20.

If you can't or don't want to move to this new version, the simplest way to protect your server is to manually remove the script links/trackback.php with the limited drawback of not accepting trackback requests for some time.

A safer version will be automatically re-installed during a next update to 7.3, so you won't have to do something specific on this after the removal.

Comments

NickR

on Mar. 21 2007


Thanks for the info.

Nick.
-----
Nick