9 Dec
2012
9 Dec
'12
10:39 p.m.
It turned out that I made a mistake by putting a private page in Main space instead of Private space. But I think I should change my admin account to prevent hacking in advance. On Mon, Dec 10, 2012 at 6:32 AM, crocket <[email protected]> wrote:
I saw tomcat.log, and I was surprised by the fact that the log was filled with " http://snowberry.me:8080/xwiki/login/XWiki/XWikiLogin;jsessionid=4EE31BA0878... "
And the log says my private pages had been hacked by access on " http://snowberry.me/xwiki/export/Main/Elisa+Slackware+Installation?format=rt... "
What the hell is going on?
I could extract private pages without logging in by accessing that URL.