Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 26

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse
Old 25.12.2004, 03:01   #1 (permalink)
Baby Mamber
 
Join Date: Dec 2004
Posts: 9
CCamacho is on a distinguished road
Default spykids ownz your server -- help

Today, my two Mambo sites had their index.php re-written with the words "spykids ownz your server". I only run Mambo on one site 4.5.1a with vBulletin, and Mambo 4.5 on the other. I DO NOT run PhpBB.

I'm running on a Virtual Host, and the server uses Plesk (latest). It's a Linux box.


I'm trying to figure out how the crackers got in. I'm nervous that this could be a Mambo hole since that is the only PHP that is running.

Running php 4.3.10.

Any ideas?

Cheers,

Carlos
p.s. please contact me at idg|atmark|mxi.netwave.or.jp if you know the secruity hole.
CCamacho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 25.12.2004, 03:19   #2 (permalink)
Baby Mamber
 
Join Date: Dec 2004
Posts: 9
CCamacho is on a distinguished road
Default Re: spykids ownz your server -- help

Here is a follow up...

No other sites on the server I am on got defaced. The main index.php file and index2.php in the Mambo folder was fine. What was altered was the index.php and index.html inside the template I was using. Very odd!

Other index.php/index.html files on my machine were fine.

So, is this a Mambo hole?

Cheers,
CCamacho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 25.12.2004, 03:53   #3 (permalink)
Baby Mamber
 
Join Date: Dec 2004
Posts: 9
CCamacho is on a distinguished road
Default Re: spykids ownz your server -- help

Yet more news...

I had my system admin search for /mambots on the server to see if there were more installs of Mambo. He found two, and sure enough... both were hit.

He mentioned files with permissions of 707.

That isn't odd because the install docs in fact say....

Quote:
chmod -R 707 images
chmod -R 707 media
chmod -R 707 uploadfiles
chmod -R 707 components
chmod -R 707 language
chmod -R 707 modules
chmod -R 707 templates
chmod -R 707 administrator/backups
chmod -R 707 administrator/components
chmod 644 configuration.php
So, I'm wondering.... should I and others follow such instructions?

Hmm.. still not sure how they were able deface, but considering templates/ content is usually set so Mambo can delete files in there... I'm not suprised.

CCamacho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 25.12.2004, 08:58   #4 (permalink)
Mamber
 
Join Date: Jul 2004
Posts: 57
sacr0 is on a distinguished road
Default Re: spykids ownz your server -- help

what is your page that got hacked? Do you have a link? to your site?

These defacement guys have a list of servers/sites they have done and I don't see any close to your email domain.( guessing your domain/or host )
In the lists from spykids I see, so far are only phpNuke and phpBB.

Without more specific information about the 'attack' it's hard to work with.

If you want real help, what do the logs say?
__________________
Imagination seeds the focus of reality
sacr0 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 25.12.2004, 09:03   #5 (permalink)
Baby Mamber
 
Join Date: Dec 2004
Posts: 9
CCamacho is on a distinguished road
Default Re: spykids ownz your server -- help

Well, after a few hours... More info has be learned.

At first, I only found the changed files in /templates

Then I found them in all directories with index.html

Then, by pointing things out to my system ad (hosting co), we were able to find more cases of bad index.html.

So, now we are confident to say that users with PhpBB on the same server caused this mess. Seems as though many of them did not patch their forums. Ahhh!!!!! To think I thought it was me...and Mambo... errrrrr!!!

Sorry for the false alarm!

Cheers,

Carlos
CCamacho is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 20.08.2005, 14:47   #6 (permalink)
Baby Mamber
 
Join Date: Sep 2004
Location: Mallorca (Spain)
Posts: 7
alexpons is on a distinguished road
Default Re: spykids ownz your server -- help

Hello Carlos, I have the same problem with spykids. The page I administrate (www.euroreptiles.com) have some index files changed. I could change with the backup files, but I'm worry they can do it again.
So, did you find a solution to keep your mambo sites of this kind of attacks?
Thanks
alexpons is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
how can i install Mambo on Server A and MySQL on another server B? kooleyo Mambo 4.5 Installation and Upgrades 11 07.08.2004 03:33
HTMLARES3_XTD-C (internal server problems) Help Please kachete Mambo 4.5 Installation and Upgrades 2 04.08.2004 16:35
internal Server error on the Apache server Polinisso Mambo 4.5 General Talk 2 19.07.2004 20:23
Server 2 Server hack code prototype -help needed TheGreek Development Discussions 0 04.06.2004 10:11


All times are GMT +2. The time now is 18:11.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.