Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Trojan Hack?
Horton
New
The facts:
I am using Vanilla 1.1.3 hosted via GoDaddy. I have not made any edits to any settings in at least a few weeks if not months. Today my users started complaining that they were getting Trojan messages from their anti-virus software. I saw it also but did not write down the name before the pop up went away. JS…. Something. (I know that does not help.)
Another note the may mean nothing…. When I looked at my site I saw that the Vanilla PHP file and the two HTML files in the vanilla root showed that they have last change dates of a few days ago. I did not do that….
Using:
Attachments 2.1
Google Analytics 1.2
JQMedia 0.6.3
ModTools 0.06.10b
Nuggets 1.1.3
Poll 1.3
Tinymce 1.4.1
See for yourself if that is a good idea.....
http://ballofspray.com/vanillaforum/
0
This discussion has been closed.
Comments
Look at your logs you might find weird requests.
Vanilla will come out with 1.1.5 shortly, so you can save that for last.
## Vanilla <= 1.1.3 Remote Blind SQL Injection Exploit
## By InATeam (http://inattack.ru/)
## Requirements: MySQL >= 4.1, magic_quotes_gpc=Off
## Tested on versions 1.1.3, 1.1.2, 1.0.1
'attack vector' used to make changes on the server. Suspect Horton has other software installed
which isn't fully patched. Being that the trojan was Pinoc, Joomla is the most likely origin.