I am currently running 2 instances of Geeklog CMS 2.2.2 in a php 8.2.28 environment.
I have been debugging along the way due to several incompatibilities and have been having great success running these websites.
Today I noticed that both of these websites were hacked with identical attacks that created a ".html" file in the sites' root folders.
The pages themselves are pretty innocuous but do represent do be an "0wn3d" situation. I am running several other NON-Geeklog sites on the same server which are not victims, so I feel confident in saying that something in Geeklog might be facilitating the hack.
Not sure if this is the place to begin digging-in to the trouble. but am wondering if anyone has any idea what might be the root of the problem?
I have read about possible trouble in admin/trackback.php and am not happy with permissions for the GUS plugin so am starting my investigations there. Is anyone else running Geeklog and getting hit with this likely "Transversal" hack/attack?
I am currently running 2 instances of Geeklog CMS 2.2.2 in a php 8.2.28 environment.
I have been debugging along the way due to several incompatibilities and have been having great success running these websites.
Today I noticed that both of these websites were hacked with identical attacks that created a ".html" file in the sites' root folders.
The pages themselves are pretty innocuous but do represent do be an "0wn3d" situation. I am running several other NON-Geeklog sites on the same server which are not victims, so I feel confident in saying that something in Geeklog might be facilitating the hack.
Not sure if this is the place to begin digging-in to the trouble. but am wondering if anyone has any idea what might be the root of the problem?
I have read about possible trouble in admin/trackback.php and am not happy with permissions for the GUS plugin so am starting my investigations there. Is anyone else running Geeklog and getting hit with this likely "Transversal" hack/attack?