Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Suspected Vulnerability Error
I installed filebrowser on a friend's directory, to get her a simple gallery, and not soon after doing so, her index.html was replaced (either that, or one showed up) using javascript which caused the page to jump all around, and had information on it that indicated her account on the server had been compromised.
http://viki.anim8or.org/evidence/index.html
is the index file. So far, superficial examinations of the file and the directory have pointed to nothing malicious, it appears as if he came in through an exploit in Filebrowser, and simply created an HTML file that makes pages jump around. We've contacted the administrator (another friend of ours) to see if this has anything to do with an old version of PostNuke which we were using at the time I installed Filebrowser if that is the source of the vunerability. I would like to request that this is looked into however, on the application end of things, typical troubleshooting procedure. I'm sure some of you guys know how it is.
Thanks in advance,
Dave
http://viki.anim8or.org/evidence/index.html
is the index file. So far, superficial examinations of the file and the directory have pointed to nothing malicious, it appears as if he came in through an exploit in Filebrowser, and simply created an HTML file that makes pages jump around. We've contacted the administrator (another friend of ours) to see if this has anything to do with an old version of PostNuke which we were using at the time I installed Filebrowser if that is the source of the vunerability. I would like to request that this is looked into however, on the application end of things, typical troubleshooting procedure. I'm sure some of you guys know how it is.
Thanks in advance,
Dave
0
This discussion has been closed.
Comments
The short scoop is that I can't possibly see how the filebrowser could be responsible. If you find that it is the filebrowser, I'd love to hear how it was accomplished.
PostNuke is notoriously insecure, especially the old versions. Our old PN site was continuously compromised, a problem which magically went away once we switched to wordpress and vanilla.