I was hit by the Spykids 2@@5 by _CaKe_ exploit of the mail_this_entry add-on this afternoon. Lately it seems that the script kiddies are finding all of their victims via Google and/or other search engines. It is very easy to type “powered by pMachine” into a web browser to find out which sites are running exploitable programs. Since the “powered by pMachine” tag is necessary to stay legal with your user agreement, I strongly suggest that anyone using pMachine replace the text with an image file. In other words, use an image that says “powered by pMachine” instead of actual text. If you use the available images from this site, I also suggest you change the name of the file to anything but its default. This way the jag who is trying to find sites to deface is less likely to find yours… even if you are vulnerable.
Also, make sure you perform that update on the main page.
Thanks.
