Members: 16,996
Threads: 38,846
Posts: 159,391
Online: 26

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse
Old 14.05.2004, 07:45   #1 (permalink)
Mamber
 
almambo's Avatar
 
Join Date: May 2004
Location: Michigan
Posts: 60
almambo is on a distinguished road
Angry MOS 4.5.1.07 Hacked

One of my sites running MOS 4.5 version 1.0.7 was hacked yesterday. Many files were uploaded on the site, among them 4843term by Havenard. I did a little research on this and found Nuke sites suffered from this about 1 year ago at the hands of a bunch of Brasiian losers. I have no idea how they gained access to the site or what, if any, MOS vulnerability was used. Heck, I am not even sure it is related to MOS. My ISP has mod_rewrite enabled and that, I have read, could be a weak link. Currently, my ISP disabled the site and I was asked to start all over! It is a nightmare to recreate the site.

Did any one experience something similar?

Thanks for any pointers.
__________________
Arabic Mambo
almambo is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 14.05.2004, 10:41   #2 (permalink)
Baby Mamber
 
Join Date: Apr 2004
Posts: 13
raetsche is on a distinguished road
Default Re: MOS 4.5.1.07 Hacked

My site running MOS 4.5.1.0.7 (MamboV4[1].5-Stable-1.0.7.tar.gz) was also hacked yesterday!
Did you also have the message
r00t_System owns your Linux!!!
id
uid=0(root) gid=0(root) groups=33(www-data)
?

Greetz
raetsche is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 14.05.2004, 10:46   #3 (permalink)
Expert Mamber
 
idigital's Avatar
 
Join Date: Apr 2004
Location: Blenheim, Queensland, Australia
Posts: 283
idigital is on a distinguished road
Send a message via ICQ to idigital Send a message via MSN to idigital
Default Re: MOS 4.5.1.07 Hacked

Sounds pretty serious. You should post over on the official Mamboserver security forum, as this is a community fan forum not an official support forum.

Maybe you could get your ISP to at least backup your database or something? They don't sound very friendly.
idigital is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 14.05.2004, 18:19   #4 (permalink)
Expert Mamber
 
pixelsoul's Avatar
 
Join Date: Apr 2004
Posts: 288
pixelsoul is on a distinguished road
Send a message via MSN to pixelsoul
Default Re: MOS 4.5.1.07 Hacked

Did you install the FCK Editor it has a exploit where people can upload stuff..
__________________
Visit my site for pro mos templates www.pixelsoul.net
pixelsoul is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 14.05.2004, 19:14   #5 (permalink)
Senior Mamber
 
TJay's Avatar
 
Join Date: Apr 2004
Location: New Orleans
Posts: 167
TJay is on a distinguished road
Default Re: MOS 4.5.1.07 Hacked

I am curious, if you only have specific registered users set with the abililty to publish, in other words only knowns can submit or edit content via the front end, and you use one of the wysiwyg editors that open this vulnerablity can people still get your site?

TJay
TJay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 14.05.2004, 19:56   #6 (permalink)
Expert Mamber
 
pixelsoul's Avatar
 
Join Date: Apr 2004
Posts: 288
pixelsoul is on a distinguished road
Send a message via MSN to pixelsoul
Default Re: MOS 4.5.1.07 Hacked

Everyone can exploit it even with the 1.6.2 .. so even if you have the editor not published for registered users.

Quote:
Originally Posted by TJay
I am curious, if you only have specific registered users set with the abililty to publish, in other words only knowns can submit or edit content via the front end, and you use one of the wysiwyg editors that open this vulnerablity can people still get your site?

TJay
Btw: Those brasillian guys defaced allot of mos sites, when mos was still on 1.0.5... also allot of the time with htmlarea which had the same problem. So it could also be possible that you did not upgrade correctly..

And remember to make backups <---
__________________
Visit my site for pro mos templates www.pixelsoul.net
pixelsoul is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 15.05.2004, 02:24   #7 (permalink)
Junior Mamber
 
jascha's Avatar
 
Join Date: Apr 2004
Posts: 26
jascha is on a distinguished road
Default Re: MOS 4.5.1.07 Hacked

For further information on this thread refer to this post:
http://forum.mamboserver.com/viewtopic.php?p=79692

Also refer to follow up for suggestions on what to do if you think your site has been 'hacked'.
http://forum.mamboserver.com/viewtop...?t=14329#79720

-Jascha
__________________
Mambo Security: http://mambosec.localareasecurity.com
jascha is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 15.05.2004, 08:32   #8 (permalink)
mmx
Expert Mamber
 
Join Date: Apr 2004
Location: Virginia Beach, Virginia USA
Posts: 309
mmx is on a distinguished road
Send a message via MSN to mmx
Default Re: MOS 4.5.1.07 Hacked

Quote:
Originally Posted by almambo
My ISP has mod_rewrite enabled and that, I have read, could be a weak link.
Read the security tutorial posted in a project on mosForge. It includes tips and tricks for securing your site. SEF support is not the only use for mod_rewrite. mod_rewrite can be used to your advantage by restricting directory access rights to selected ip addresses.
mmx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 15.05.2004, 23:50   #9 (permalink)
Junior Mamber
 
jascha's Avatar
 
Join Date: Apr 2004
Posts: 26
jascha is on a distinguished road
Default Re: MOS 4.5.1.07 Hacked

Yes, I hear that is a very good paper.
(See my sig for punchline)

-Jascha
__________________
Mambo Security: http://mambosec.localareasecurity.com
jascha is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 16.05.2004, 00:28   #10 (permalink)
mmx
Expert Mamber
 
Join Date: Apr 2004
Location: Virginia Beach, Virginia USA
Posts: 309
mmx is on a distinguished road
Send a message via MSN to mmx
Default Re: MOS 4.5.1.07 Hacked

Extremely useful tutorial because it minimizes frequently asked security questions to almost nothing. Tony and I need to hook up with you later when we start to work on the security chapter for the MOS 5.0 book.

Quote:
Originally Posted by jascha
Yes, I hear that is a very good paper.
(See my sig for punchline)

-Jascha
mmx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Is this a bug or am I hacked???? Entire Mambo 4.5 General Talk 5 12.04.2004 18:41


All times are GMT +2. The time now is 17:45.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.