PDA

View Full Version : Guestbook was hacked


vqueen
05-20-2005, 12:29 AM
When people tried to access the guestbook (even when i tried from the control panel), we keep getting redirected to a porn site :eek: which is very upsetting since the site is for a storyteller for children.

I had to disable the ultraguest guestbook. :( Can the admi do something about this please? My other ultraguest guestbook hasn't been touched. Just the other one.

Thank you.

Andreas
05-20-2005, 02:36 AM
What is the guestbook ID (or URL)? I tried to check the guestbook associated with your email but it appears be working.

There are two possibilities here:

Someone has left a message which somehow forwards the user to an adult site. In this case there is a bug in the guestbook system, since "dangerous" html, javascript etc is supposed to be removed from all posts.
Someone accessed to the members area using your email and your password, and changed the header of your guestbook. Javascript etc is allowed here which makes redirects possible. This would not be a bug in the system.

vqueen
05-20-2005, 03:05 AM
The guestbook ID is 1116010034. I tried to access from the control panel and I still got the porn sites. I can't close the sites since it opens multiple browser windows and I have to restart my computer.

Andreas
05-20-2005, 03:54 AM
Hi,

This was indeed a bug in the guestbook system.

Malicious messages has now been removed from your guestbook and a bug that lets people post certain code in the "Name" field has been fixed.

Thanks for reporting this problem and making UltraGuest.com better! :)