<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PHP User-Group Philippines &#187; hacked</title>
	<atom:link href="http://www.phpugph.com/blog/tag/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.phpugph.com/blog</link>
	<description></description>
	<lastBuildDate>Wed, 23 Dec 2009 04:00:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Update: PHPUGPH&#8217;s SMF maliciously attacked. Now back online</title>
		<link>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/</link>
		<comments>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 15:33:46 +0000</pubDate>
		<dc:creator>aj</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[krisbarteo]]></category>
		<category><![CDATA[phpugph]]></category>
		<category><![CDATA[smf]]></category>

		<guid isPermaLink="false">http://www.phpugph.com/blog/?p=49</guid>
		<description><![CDATA[I&#8217;ve done an audit on the files of phpugph.com&#8217;s SMF board and found that a certain user who&#8217;s only identity is krisbarteo@gmail.com using the IP 94.142.129.147 appended spam links to the Settings.php of SMF.
I&#8217;m no security expert, but I think what he did was he uploaded an avatar with a PHP code inside it, found [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve done an audit on the files of phpugph.com&#8217;s SMF board and found that a certain user who&#8217;s only identity is krisbarteo@gmail.com using the IP <a href="http://www.stopforumspam.com/ipcheck/94.142.129.147">94.142.129.147</a> appended spam links to the Settings.php of SMF.</p>
<p>I&#8217;m no security expert, but I think what he did was he uploaded an avatar with a PHP code inside it, found a server/script exploit and ran it. I opened up the avatar (after looking for it for hours) and found this code (see below screenshot). Then he launched the attack from there appending malicious links on a file that is being included everytime SMF draws a page.</p>
<p><img class="alignnone" title="1" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/1.jpg" alt="" width="400" height="246" /></p>
<p><img class="alignnone" title="2" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/2.jpg" alt="" width="400" height="98" /></p>
<p>A quick Diff on SMF&#8217;s base files and our SMF files revealed that a new readme.php was created. And it contained the following:</p>
<p><img class="alignnone" title="3" src="http://www.phpugph.com/blog/wp-content/uploads/2009/06/3.jpg" alt="" width="400" height="299" /></p>
<p>Decoding that garbled texts reveals that readme.php was run on the browser and that was the main cause of appending links on the Settings.php.</p>
<p>I am still baffled by the fact that some people would do such things. Disrupt service for profit? Well, as for  krisbarteo, yes you&#8217;ve succeeded in doing that. Then what? Happy now? If you only have used that smarts and skills on the good stuff, you&#8217;d probably be rich by now.</p>
<p>To all PHPugers, we hope that this thing doesn&#8217;t happen again even if we all know that the Internet isn&#8217;t safe from these crackers. It&#8217;s all good. For now.</p>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.phpugph.com%2Fblog%2F2009%2F06%2F24%2Fupdate-phpugphs-smf-maliciously-attacked-now-back-online%2F&amp;layout=standard&amp;show-faces=true&amp;width=450&amp;action=like&amp;font=arial&amp;colorscheme=light" scrolling="no" frameborder="0" allowTransparency="true" style="border:none; overflow:hidden; width:450px; height:auto;"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.phpugph.com/blog/2009/06/24/update-phpugphs-smf-maliciously-attacked-now-back-online/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
