Thanks for that, I've fired off an enquiry to them. I've a client's listing on that site so it doesn't reflect well on them.
http://www.emailesurance.com/ mine went down last night not hacked though ,just some gliitch in the database.shit happens.
I wonder when people know that script is vulnerable to such attack, why they keep using it??? Have seen such news about index script so many times recently.
Once my sites were hacked, i stopped using it, but it wasn't meant in any disrepectful way to the creator, as he announced that it is mostly just a hobby for him, i can fully appreciate that and understand that he may not be able to update the script as often as expected, and its a case of use at your own risk. It did me for 3 of my directories, to start off with at least, i got nervous when i saw that the main site had been hit that time.
To be fair, the creator did come up with a fix within about a day. What I think is pertinent is the way these scripts were found. The hacked directories probably all had "Powered by Indexscript" in the footer, and it would be very easy for the crackers to find them all using a simple search. So no matter what script you're using, it will most likely pay dividends to remove common footprints such as this. Get the paid-for version that allows you to remove the footer link, and change all the default text.
I run PhpLD on each of my directories now, but when i have the money i will pay the extra $50 for removal of the backlink to them. I agree, for a few reasons i think its a good idea. When you say change all the default text, where are you referring?
It depends on the script, I'm not just talking about directory scripts but any common ones. But one of the common things with phpld is the default text you get on the submit page, the standard text for the navigation links, common category dumps, and so on.
I got you now, try and change some of that where ever possible, whilst still leaving nav links etc making sense, a good idea. Thanks
need to correct that one there... sorry, but there has been only 1 attack on indexscript so far and i released a fix the same day... no other attacks... so am not sure what you mean by so many times recently...