Discuz!官方免费开源建站系统

 找回密码
 立即注册

QQ登录

只需一步,快速开始

搜索

DZ X2有漏洞导致数据库死锁

[复制链接]
itlietou1 发表于 2014-3-18 14:53:16 | 显示全部楼层 |阅读模式
本帖最后由 itlietou1 于 2014-3-18 14:55 编辑

近期连续发生问题,详细请见:
https://discuz.dismall.com/thread-3523296-1-1.html
和后台网管联系,确认是DZ X2有漏洞,导致黑客攻击:
The dizcuz software you are using appears to have a security issue, which
is allowing an attacker to put sleep() statements into queries and take
down your site.  They could just as well destroy your database, read its
data or modify data as well, so it is important to upgrade and not just
block the attackers IP address, or reboot mysql when they break your
database.
我想知道的是:
1.DZ对X2是否会有什么补丁的打算
2.真的升级到X3.1之后这个问题就会解决吗?
——————————————————————————————
错误如下(很简单):
Discuz! Database Error
The database has encountered a problem. Need Help?

Error messages:
  • [Type] 无法连接到数据库服务器
  • [1203] User ciscofan already has more than 'max_user_connections' active connections
Program messages:
  • [Line: 0128]index.php(require)
  • [Line: 0018]portal.php(discuz_core->init)
  • [Line: 0065]source/class/class_core.php(discuz_core->_init_db)
  • [Line: 0364]source/class/class_core.php(db_mysql->connect)
  • [Line: 0764]source/class/class_core.php(db_mysql->_dbconnect)





btw,我的是DZ2,几年前就从X1.5升级到X2,一直都没问题,连续发生此问题(2周内4-5次)。

pcyi 发表于 2014-3-18 16:30:40 | 显示全部楼层
没发现这个问题,这是神马漏洞?看看其他X2成员的站点有没有这个问题。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

手机版|小黑屋|Discuz! 官方站 ( 皖ICP备16010102号 )star

GMT+8, 2025-3-11 10:34 , Processed in 0.022253 second(s), 4 queries , Gzip On, Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2023, Tencent Cloud.

快速回复 返回顶部 返回列表