Phishing script

Someone uploaded a phishing script to my Dolphin 6.1.4 Free site

The phishing page is here: http://www.dlive-entertainment.com/admin/default_builders/hsbc.co.uk-HSBCINTEGRATION-IBlogin.html http://www.dlive-entertainment.com/admin/default_builders/hsbc.co.uk.htm http://www.dlive-entertainment.com/admin/default_builders/sct.htm

I host at hostmonster.com

How could they get there. I did a clean install.

Regards,

Harvliet

Quote · 5 Oct 2008

Hello!

Usual ways of similar hacks - uplaod malice files using enabled REGSITER_GLOBALS variable and directories with 777 permissions without forbiding .htaccess files within.

Ask your hosting to disable register globals because as i remember hostgator hostings don't allow to use php_flag register_globals Off in main .htaccess file.

Regard

Quote · 6 Oct 2008
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.