Acrionscript.org Hacking Revealed
Posted February 18, 2004 by senocular
ZDNet UK has the dirt on what happened a few weeks ago when Actionscript.org was hacked. Apparently there's a "a vulnerable PHP script in EMML (EternalMart Mailing List Manager)".
I can't say that sounds good.
The hackers rigged a backdoor into the site by manipulating the PHP script using a Web browser. Using a very complicated URL, the hackers were able to make the faulty PHP script download and compile code stored on a remote site, said Stratford. Once compiled, the code allowed anyone to log in to actionscript.org's server with root [administrative] privileges, giving the hackers free reign to wreak havoc with the system.
I can't say that sounds good.