We build. You grow.

Get best community software here

Start a social network, a fan-site, an education project with oxwall - free opensource community software

Our website keeps getting hacked | Forum

Topic location: Forum home » Support » General Questions
Woot
Woot Nov 3 '13
Our website keeps getting hacked and we just found out that people can use a script called c99shell which can disguise this php file as an image and be uploaded.


We got our friend to test out this hacked-script on our site to find out what is happening. And it appears that if he disguises the PHP file as an image then he can upload it as a background or an avatar, if he uploads as an avatar the outcome is that all of our avatars disappear. 


If he uploads it as a background then we get a backdoor viruses on our PC's.


Now we are wondering where the directory to editing Avatar Uploading and picture uploading and I want to find a way to prevent it on the customprofile plugin that was made by Paul Cuffe.

Joshua
Joshua Nov 23 '13
Whoa! I would definitely like some more information to confirm this is an Oxwall problem and not something else...