• Our software update is now concluded. You will need to reset your password to log in. In order to do this, you will have to click "Log in" in the top right corner and then "Forgot your password?".
  • Welcome to PokéCommunity! Register now and join one of the best fan communities on the 'net to talk Pokémon and more! We are not affiliated with The Pokémon Company or Nintendo.

AWStats Vulnerability!

Kipkip

Join the Revolution
968
Posts
20
Years
    • Age 33
    • Seen Jun 24, 2007
    If you are running AWStats version 6.2 or lower, please upgrade to 6.3. This vulnerability "..allows the execution of arbitrary commands on a server, effectively giving malicious hackers complete control over the machine." Some you may know that https://phpbb.com has been hacked using this expliot. It was not caused by phpbb so as long as you have phpbb 2.0.11, you're good. But if you are running AWStats 6.2 or lower, upgrade now.

    Source:
    https://www.eweek.com/article2/0,1759,1763152,00.asp
    https://phpbb.com/
     

    Kipkip

    Join the Revolution
    968
    Posts
    20
    Years
    • Age 33
    • Seen Jun 24, 2007
    Imakuni? said:
    Fortunatly, I dunped phpBB...
    Switch to vB, save your server...
    It is not phpbb's fault. You could use vB(worse in my opinion. Not free, not open-sourced?!?! :shocked: ) or absoulty no forum software at all and you can still be vulnerable if you use AWStats with the version 6.2 or lower.
     

    Kipkip

    Join the Revolution
    968
    Posts
    20
    Years
    • Age 33
    • Seen Jun 24, 2007
    Imakuni? said:
    oh, so its a phpBB addon?
    It's a stat system like HellishHades said. It's usually in the CPanel under stats or at least that's where mine is.
     
    Back
    Top