[Coco] iframe trojan link removed

Roger Taylor operator at coco3.com
Sat Feb 10 13:41:56 EST 2007


Good News about the CoCo forums...

I found the iframe tag in one of the forum template files, and 
removed it.  I'm going to research how these hackers are doing this 
and try to patch the system to intercept these attacks.  I suspect it 
was a MySQL injection through a security hole in the calendar.php 
module.  This was proven possible by advanced PHP hackers.  Nobody 
used the calendar anyway, so it has been removed completely.  The 
link still exists until I have time to remove it as well.

Thanks to everyone who has reported spam and hacker activity in the 
forums, and to those who help moderate the postings.

The spam and hacker battle is something no webmaster is immune to and 
each day there are new tactics invented to hurt us.  But thanks to 
these cat and mouse games, I am somewhat behind on my CoCo orders.

If you've ordered a product from the site and are wondering when 
you'll get it, just know that I'm working on them in turn as received 
and that you're in queue.  The CoCo TV DVD orders were "preorders" 
until a few weeks ago when it was officially released.  For those who 
made an order months back and didn't know it was a preorder for 
something that was not complete, I'm sure you're getting impatient, 
but rest assured yours is coming soon.

Thanks,
Roger Taylor


-- 
Roger Taylor





More information about the Coco mailing list