2012-05-12, 02:29:54
I suggest everyone deletes their GS cache.
It is all infected from the plugin api caches.
Well mine are, but Im not sure where its coming from yet, since it doesn't show up when i do a direct call.
Well I don't see the injection when direct accessing via my browser, but my curl and get_file_contents both return a script injection.
Either GS is compromised or I have some local injection on my host.
If someone could open a new cache file from the api
gs/data/cache md5.txt
and see if it contains script tags.
It is all infected from the plugin api caches.
Well mine are, but Im not sure where its coming from yet, since it doesn't show up when i do a direct call.
Well I don't see the injection when direct accessing via my browser, but my curl and get_file_contents both return a script injection.
Either GS is compromised or I have some local injection on my host.
If someone could open a new cache file from the api
gs/data/cache md5.txt
and see if it contains script tags.