English Bug tracker

SECURITY ALERT [Intégré]

Bernard Paques -- le 20 mar. 2007 à 16:39 GMT, depuis nearby-an-airport
[b]YACS Leader[/b]

Please remove script links/trackback.php manually from your server

PropriétaireBernard Paques
Avancement100%
WorkflowBesoin d'aide
StatutLa solution a été intégrée
We have been reported one site running YACS 7.2 hacked. The root case analysis has shown repeated attacks on the aforementioned script. Flaws identified here have been fixed in the archive 7.3alpha19 released on March-20.

If you can't or don't want to move to this new version, the simplest way to protect your server is to manually remove the script links/trackback.php with the limited drawback of not accepting trackback requests for some time.

A safer version will be automatically re-installed during a next update to 7.3, so you won't have to do something specific on this after the removal.