Archive for August, 2005

Exploit Found

Thursday, August 25th, 2005

I’ve determined what the exploit is; I’ll have it closed up by midnight tonight.

I’ve had the exploit hole patched for 90 minutes; Mark Smiley called, so I talked to him rather than updating here.

Server Temporarily Unreachable

Wednesday, August 24th, 2005

I rebooted the server as part of my investigation into the recent XSS exploit, and the server is unreachable by ping. The datacenter is working to restore this condition.

The server is back online.

Cross Site Scripting Exploit

Wednesday, August 24th, 2005

We have suffered this past week from some Cross Site Scripting exploits this week. I ask that all users please contact me if they have installed something outside of phpBB or WordPress on this machine.