Hi guys!
My site was hacked through, as I think, vulnerabilites of CKForms 1.3.2.
Tonight I was trying to access my site and instead of it's content I saw a screen of some exploit (see attachment). When I had connected by FTP client there was only 3 files:
htaccess
error_log
index.php
the time of creation of index.php and error_log was different and newer than old date of htaccess.
The content of error_log was:
[23-Apr-2010 09:15:57] PHP Fatal error: Class 'CkformsController../../../../../../../../../../../../../../../../proc/self/environ' not found in /home/u57322ru/public_html/pslon.ru/components/com_ckforms/ckforms.php on line 24
And this date and time was the same as the time of creation index.php.
The content of index.php is in attacment (too big to post).
I was "very happy" and restored all the content of site from backup. After that, in about 30 minutes I was hacked again with the same result.
I do not ask for support of any kind becouse I didn't buy CKForms but I guess this could be essential for users of any kind.
Best regards,
Yuri