Members: 16,996
Threads: 38,845
Posts: 159,389
Online: 19

Newest Member: Kl_broka@rediffmail.com


Odoo.tv - Outdoor Television


Sedo - Domains kaufen und verkaufen das Projekt mambers.com steht zum Verkauf Besucherstatistiken von mambers.com etracker® Web-Controlling statt Logfile-Analyse

Go Back   Mambers.com > Archive > Mambo 4.5 > Mambo 4.5 Security

 
 
LinkBack Thread Tools Display Modes
Old 22.12.2004, 01:19   #1 (permalink)
Junior Mamber
 
heyjoe's Avatar
 
Join Date: Apr 2004
Posts: 43
heyjoe is on a distinguished road
Angry Site hacked /defaced today

Today (22/12/04) I found my site www.helpmij.info defaced :All over the page I see

This site is defaced!!!


NeverEverNoSanity WebWorm generation 18.

It was an Old 1.07 site, but I made so many adjustments I did not dare to upgrade....
Can anyone tell me how I can get rid of the Deface and where to find a Update package to 1.09. I do not want to total overwrite my existing installation....
heyjoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Old 22.12.2004, 01:24   #2 (permalink)
Junior Mamber
 
anandus's Avatar
 
Join Date: Aug 2004
Posts: 34
anandus is on a distinguished road
Default Re: Site hacked /defaced today

See this topic:
Sites hacked !!
__________________
Biologypages
anandus is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 01:25   #3 (permalink)
Baby Mamber
 
Join Date: Jul 2004
Posts: 1
Cartika is on a distinguished road
Default Re: Site hacked /defaced today

Hello,

Yes, you can download the 1.07>1.08 upgrade and ftp to your site. You then need to download and ftp the 1.08>1.09 upgrade.

You may not want to upgrade to 4.5.1a - however, there were many security exploits covered in the 1.08 and 1.09 patch - upgrading from 1.07 will not affect your modules/components or any other DB structure - however, it will address several security exploits.
Cartika is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 01:57   #4 (permalink)
Junior Mamber
 
heyjoe's Avatar
 
Join Date: Apr 2004
Posts: 43
heyjoe is on a distinguished road
Default Re: Site hacked /defaced today

I saw that many sites of my provider were defaced. They scream not to have files CHModded to 777 and they need to upgrade some things...
heyjoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 01:58   #5 (permalink)
Junior Mamber
 
heyjoe's Avatar
 
Join Date: Apr 2004
Posts: 43
heyjoe is on a distinguished road
Default Re: Site hacked /defaced today

I looked at mamboserver further. I don't find the UPDATEpackage to 1.08 / 1.09 Where do I find these.....
heyjoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 02:51   #6 (permalink)
Baby Mamber
 
Join Date: Oct 2004
Posts: 9
lumsum is on a distinguished road
Default Re: Site hacked /defaced today

Hi
U can download Patch 1.0.8 - 1.0.9 here.
http://mamboforge.net/frs/download.p...9-patch.tar.gz
lumsum is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 10:58   #7 (permalink)
Junior Mamber
 
heyjoe's Avatar
 
Join Date: Apr 2004
Posts: 43
heyjoe is on a distinguished road
Default Re: Site hacked /defaced today

Well I think this is the patch, not the upgrade package...
or am I mistaken here ???
heyjoe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 11:09   #8 (permalink)
Mamber
 
Heart's Avatar
 
Join Date: Apr 2004
Location: near Munich, Germany
Posts: 119
Heart is on a distinguished road
Default Re: Site hacked /defaced today

Same problem here "This site is defaced!!! NeverEverNoSanity WebWorm generation 6."...

But can you please explain me what I have to do that I can fix this so that all components and modules work again?

I read mambo isn't the problem, so an upgrade to 1.0.9 isn't the solution, is it?
Heart is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 17:58   #9 (permalink)
Junior Mamber
 
jascha's Avatar
 
Join Date: Apr 2004
Posts: 26
jascha is on a distinguished road
Default Re: Site hacked /defaced today

Seems about 400 others have this issue too.

More on this:

Symantec

Secunia Full Listings

-Jascha
__________________
Mambo Security: http://mambosec.localareasecurity.com
jascha is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Old 22.12.2004, 18:21   #10 (permalink)
Expert Mamber
 
pflegeonline's Avatar
 
Join Date: Apr 2004
Location: Schladming/Graz
Posts: 414
pflegeonline is on a distinguished road
Default Re: Site hacked /defaced today

Take out the 6 and only search after "NeverEverNoSanity WebWorm generation" -> 1.480 Sites defaced.

http://www.google.com/search?hl=de&c...neration&meta=


There are 18 generations of NeverEverNoSanity defacing sites!
__________________
pflegeonline is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sites hacked !! rascal71 Community Announcements 24 23.12.2004 16:44
site hacked ingmar Community Arena 4 08.11.2004 18:36
Site Hacked by Vn Truehack fuzzybuster Mambo 4.5 Security 8 07.09.2004 03:22
My site was hacked, need some help pls stracken Mambo 4.5.1 'How Do I' Questions 3 31.08.2004 18:08
phil's site hacked? andreadesign Community Arena 33 30.05.2004 19:57


All times are GMT +2. The time now is 21:53.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0
A vBSkinworks Design
© Copyright 2004-2008 by Arthur Konze Webdesign.