Posted: Tue Feb 26, 2008 5:47 pm Post subject: Hacked by phisher
I work for a local high school and over the last three days have been contacted by two banks about our domain housing a phish site affecting their customers.
I have isolated the files and removed them from our web server. Does anyone have suggestions on how to black attacks like this from happening on our web server? Our web is hosted on a MAC server and our website is currently using php 4.4.7
Having secure applications and keeping them up to date will help.
from php.net
Quote:
PHP 4 end of life announcement
[13-Jul-2007]
Today it is exactly three years ago since PHP 5 has been released. In those three years it has seen many improvements over PHP 4. PHP 5 is fast, stable & production-ready and as PHP 6 is on the way, PHP 4 will be discontinued.
The PHP development team hereby announces that support for PHP 4 will continue until the end of this year only. After 2007-12-31 there will be no more releases of PHP 4.4. We will continue to make critical security fixes available on a case-by-case basis until 2008-08-08. Please use the rest of this year to make your application suitable to run on PHP 5.
For documentation on migration for PHP 4 to PHP 5, we would like to point you to our migration guide. There is additional information available in the PHP 5.0 to PHP 5.1 and PHP 5.1 to PHP 5.2 migration guides as well.
_________________ "Anyone who considers protocol unimportant has never dealt with a cat."
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum