Remote file inclusion exploit reappeared?

Discussion in 'Troubleshooting' started by gnicholas, Jul 24, 2007.

  1. gnicholas

    gnicholas New Member

    Joined:
    Feb 14, 2007
    Messages:
    4
    I've noticed a number of entries in my logs that appear to show successful remote file include exploits to reveal the user running Apache.

    Amember 3.0.8PRO (ie. latest version) running on RHEL, with register_globals off.

    Other attempts are visible in the logs. Many 403s, but some 200s. Search on 'amember' and 'mysql' to check for attempts in your own logs.

    I've logged this as an urgent request with tech support, but no response as yet.

    Has anyone else experienced this?
  2. alexander

    alexander Administrator Staff Member

    Joined:
    Jan 8, 2003
    Messages:
    6,279
    This is not as issue. Someone just tryed to use old exploit that was fixed a long time ago.

Share This Page