Help - Search - Members - Calendar
Full Version: cgi-bin poll hacked?
The Planet Forums > Security > General Security
qwertyjoe
I have a poll on my website. I went to change it this morning and the data file that contains the votes is normally like this....

CHOICES|||1|||0|||0|||0|||0|||0
IPS|||0.0.0.0|||0.0.0.0|||0.0.0.0|||0.0.0.0|||0.0.0.0|||23.xx.xx.68

This morning it was like this....

䡃䥏䕃籓籼簰籼簰籼簰籼簱籼簰籼簱籼簱籼簱籼簲籼簰籼簱籼簰籼簰籼簱籼簰籼簱籼簱籼簱籼簱籼ള䤊卐籼㝼⸱ㄵ㘮⸰㠶籼㉼㤰ㄮ㜰ㄮ㠸ㄮ〷籼ㅼ⸲㜳㜮⸶㤶籼㉼㘱ㄮ⸷㌲⸰〱簵籼〲⸴㈱⸴㈱⸲㔱簱籼〲⸲㐱㈮㜴㐮

I checked 'history' on my server and nothing was new. What should I do? How was this done? Thanks for any help. And does anyone read Chinese or whatever language this is?
markcausa
Hmmm, maybe a control panel updated messed it up?
qwertyjoe
QUOTE (markcausa @ Jan 2 2008, 04:37 AM) *
Hmmm, maybe a control panel updated messed it up?


I hope so. Nothing else has happened (that I'm aware of). Thanks for the reply.
markcausa
No prob. You running cPanel?
qwertyjoe
Yes, Cpanel. It's been a few days and still nothing. Hoping it was a glitch.
markcausa
Hmmm, were you able to get the poll fixed atleast? If so, how?
qwertyjoe
QUOTE (markcausa @ Jan 5 2008, 10:15 PM) *
Hmmm, were you able to get the poll fixed atleast? If so, how?


There was never a problem with anything except the data file that records the votes was in the Chinese or gibberish. Each time I put up a new poll I delete the data file and a new one is created with the first vote. I'm hoping it was just a fluke of some kind. Nothing new has happened (that I'm aware of). Knock on wood!
James Jhurani
If they were trying to cause a buffer overflow the corruption may have been due to the garbage they were inputting to cause the overflow...

It happens... I would suggest looking up the version of the poll you are using, and making sure it is the most up to date version available.
markcausa
Ooo, what's a buffer overflow?
James Jhurani
QUOTE (markcausa @ Jan 6 2008, 10:56 PM) *
Ooo, what's a buffer overflow?



http://en.wikipedia.org/wiki/Buffer_overflow
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.