Results 1 to 7 of 7

xss injection question

This is a discussion on xss injection question within the General Discussion forums, part of the vBSEO SEO Plugin category; Anyone else seen this thread? Iframe MYSQL Injection (http://centiyo.com/in.cgi?default) Looks like we had it happen on one of our sites ...

  1. #1
    Member
    Real Name
    Dascrow
    Join Date
    Mar 2007
    Location
    Alamogordo, NM
    Posts
    37
    Liked
    1 times

    xss injection question

    Anyone else seen this thread?

    Iframe MYSQL Injection (http://centiyo.com/in.cgi?default)

    Looks like we had it happen on one of our sites today... and we are running 3.8.4pl1 on that site as well with the latest vbseo so upgrading is not an option.

    Anyone else?

    VBSEO? I just opened a ticket.

  2. #2
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    22,367
    Liked
    542 times
    Blog Entries
    4
    Hello ,

    I responded to your ticket
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  3. #3
    Member
    Real Name
    Dascrow
    Join Date
    Mar 2007
    Location
    Alamogordo, NM
    Posts
    37
    Liked
    1 times
    What about anyone else out there?

  4. #4
    vBSEO Staff Juan Muriente's Avatar
    Real Name
    Juan Carlos Muriente
    Join Date
    Jun 2005
    Location
    Puerto Rico
    Posts
    14,267
    Liked
    558 times
    Hello Dascrow,

    There is no evidence that this is a hole with vBSEO, therefore, I'll update the title of this thread as to not create anxiety among community members.

    If we determine it's something related to vBSEO, we'll definitely make sure everyone gets notified.

    Thank-you
    Juan Muriente / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  5. #5
    Member
    Real Name
    Matthew
    Join Date
    Mar 2009
    Posts
    60
    Liked
    0 times
    To repost what I put in that thread; (hope this is ok with the vbseo guys)

    3.3.2 was a patchreleased on November the 18th to fix a security loophole. Why you haven't updated yet is beyond me.

    I literally applied it within minutes of getting the email.

    Sounds like your own fault for not keeping on top of things.

  6. #6
    vBSEO Staff Juan Muriente's Avatar
    Real Name
    Juan Carlos Muriente
    Join Date
    Jun 2005
    Location
    Puerto Rico
    Posts
    14,267
    Liked
    558 times
    Quote Originally Posted by Dunhamzzz View Post
    To repost what I put in that thread; (hope this is ok with the vbseo guys)
    Thank-you Matthew, however I've based my post on the information gathered via the support ticket Dascrow has opened. I simply changed the post title as there is no evidence that his site exploit was caused by a hole in vBSEO.
    Juan Muriente / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  7. #7
    Member
    Real Name
    Dascrow
    Join Date
    Mar 2007
    Location
    Alamogordo, NM
    Posts
    37
    Liked
    1 times
    Quote Originally Posted by Dunhamzzz View Post
    To repost what I put in that thread; (hope this is ok with the vbseo guys)
    And also, as mentioned in that other thread, this is a new site and as such had 3.3.2 on it from day 1. So your post is obviously invalid in my case.

    So, either they got in via another method or vbseo is still vulnerable. It is impossible for me to tell what method was used at this time.

Similar Threads

  1. Redid my DevilsOwn water Injection again :)
    By rocket468 in forum Critique Please
    Replies: 3
    Last Post: 06-01-2009, 01:34 PM
  2. Strange code / caracter injection above header / below footer *argh*
    By Doc Great in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 02-22-2007, 03:57 PM
  3. Vbseo Skin Beta for alcohol-injection.com
    By rocket468 in forum Analysis: Traffic & SERPS
    Replies: 10
    Last Post: 01-31-2007, 04:07 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •