Activity Stream
48,167 MEMBERS
6696 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 1 of 2 12 LastLast
Results 1 to 10 of 17
  1.     
    #1
    Member
    Website's:
    rootw.net

    Default ddlcms exploit

    Does anyone know the ddlcms exploit so i can patch it?
    narutoroot Reviewed by narutoroot on . ddlcms exploit Does anyone know the ddlcms exploit so i can patch it? Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Respected Developer
    If you can patch exploits it shouldn't be hard to find the exploit if any exist

  4.     
    #3
    Member
    Website's:
    rootw.net
    of c ourse i want like what to replace and stuff. plus i dont have time to look through the whole script lol

  5.     
    #4
    Member
    Yes there are exploits for it.
    ▄▀▄ HosterBin Inc.
    ▄▀▄ Webs Hosting, VPS, Dedicated Servers
    ▄▀▄ http://www.hosterbin.com support@hosterbin.com

  6.     
    #5
    Respected Developer
    Can you even confirm someone has found an exploit in the script and isn't just exploiting poorly secured sites (server config or whatever)? Well either way, I doubt any of us will go trough every line of code to find out.

  7.     
    #6
    Member
    There is an exploit out there for this script that i can download their sql with all submissions ect.
    ▄▀▄ HosterBin Inc.
    ▄▀▄ Webs Hosting, VPS, Dedicated Servers
    ▄▀▄ http://www.hosterbin.com support@hosterbin.com

  8.     
    #7
    Member
    Website's:
    rootw.net
    you have it?

  9.     
    #8
    Respected Developer
    http://www.ddlcms.com/forums/index.p...rum=2&topic=94

    Turn off allow_url_include on your host. Ask your host or go to your php.ini to change it to off. You can also do it via WHM, go to PHP Configuration Editor, then click on Advanced. Turn allow_url_include to "off" and then click Save.
    Have fun patching.

    Something about configuration *cough*...

  10.     
    #9
    Member
    Website's:
    rootw.net
    thanks-----

  11.     
    #10
    Member
    Two things,

    There is probably always an exploit in some code, and that's one of them. DDL CMS I think has it patched in an upcoming release which is apparently right around the corner.

    Second all this does is allow somebody to download your SQL database...which quite frankly I could careless about. Good luck trying to hack anything from that database, and besides most sites using this will have just a big warez database of files which you can upload to your site lol.

    Anyhow good that it's being fixed.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. 0-day WHCMS exploit
    By shadow.prx in forum General Discussion
    Replies: 3
    Last Post: 1st Jun 2012, 01:21 AM
  2. Windows RDP Exploit
    By JamesVaporH in forum Hosting Discussion
    Replies: 0
    Last Post: 18th Mar 2012, 05:57 PM
  3. WHMCS Exploit attacks.
    By dotvps in forum Hosting Discussion
    Replies: 21
    Last Post: 10th Dec 2011, 12:24 PM
  4. [Selling] [Exploit] Hot Exclusive YouTube Exploit [New]
    By Goob3r in forum Completed Transactions
    Replies: 1
    Last Post: 24th Aug 2010, 04:21 PM
  5. Buying exploit
    By mr.oug in forum Completed Transactions
    Replies: 6
    Last Post: 28th Dec 2008, 09:37 AM

Tags for this Thread

BE SOCIAL