phpCOIN vulnerability fix

phpCOIN is the software used by BryteNet hosting to manage orders, invoicing and the helpdesk. Tuesday a vulnerability has been discovered allowing atackers to execute remote code on the server.

When a fix was published I immediately installed it on the server, but the site had already been hacked. To make matters worse, the fix files contained errors, which made that phpCOIN did not produce any output. My server error log showed me where the errrors were, and by adding some parentesis I could fix my site. The official fix files are now three days old, and still contain these errors. There are more and more people running into this problem asking for wroking, so I uploaded my fixed files for download. Note that the original fix file contains more files, so you need to install those files first and then overwrite the three files with errors with my copies.

[Update 2005/12/19]: The official fix files have been updated, so my files are no longer necessary.

Leave a comment

mensuales Archives

Recent Entries

  • Manifiesto «En defensa de los derechos fundamentales en internet»

    Ante la inclusión en el Anteproyecto de Ley de Economía sostenible de modificaciones legislativas que afectan al libre ejercicio de las libertades de expresión, información...

  • Commenting not possible

    I just discovered that it currently is not possible to comment on this blog. At first sight it looks like the problem is caused...

  • Back from the CeBIT

    I am back from the CeBIT show. Actually, I came back on Monday, but have been too busy to post. This year has been...

  • Downloading viruses?

    I just saw the screen above, which is the ClamWin antivirus software uploading its virus database. On the left hand side they have an animation...

  • New: Google Notebook

    I know that Spain usually lags behind the rest of the world, but Google Spain really doesn't know what is going on. While all...

Close