Welcome, Guest. Please login or register.
Did you miss your activation email?
May 27, 2012, 04:37:33 AM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite.
155555 Posts in 21715 Topics by 7737 Members
Latest Member: gx-world
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: some of my WB sites are hacked(with diferent homepages)  (Read 791 times)
giorgiomx

Offline Offline

Posts: 11


« on: February 01, 2008, 12:58:08 AM »

Hi

Some of my WB sites are being hacked, they're probably early versions, I think 2.6.4.
Should 2.6.7 fix the issue?

they seem to be different hackers.
So far I have found these.
these are some examples of 4 homepages I moved
http://www.dptielectronics.com/index3.php
http://www.ryga.com.mx/index2.php
http://www.coffeedesigners.com.mx/index2.php
http://www.comercialmega.com/index2.php

The config.php of those sites had its contents replaced for the content you see on the homepage

The server is very good on security, so is very probable something related qith WB's files.

There are no modules installed, just WB as is.

Any suggestions?


thank you

Giorgio
Logged
RedGnomos

Offline Offline

Posts: 65


« Reply #1 on: February 01, 2008, 02:51:49 AM »

You may find a solution here - http://www.frsirt.com/english/advisories/2007/0311/solution or here http://www.phpsecure.info/v2/?zone=pVulns&aid=4799&l=us. You may need to perform a search.
Logged
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7973



WWW
« Reply #2 on: February 01, 2008, 06:55:47 AM »

Hello,

1.) Please use the latest version of WB (2.6.7) and the FCKEditor (2.81). All described issues from WB in the link from RedGnomos are only in earlier versions (see the dates are all befor 2007) and fixed in the actually version.

2.) All pages wich was hacked, was hacked on unsecure servers. To overwrite the config.php or the index.php can only be done from a hacker wich has full access to the server. This is not possible through WB. So please ask your hoster for the server logs. There you will see when and how the files are changed. I'm pretty shure you will not got this infos from your hoster as he will recognize in these logfiles that his server config is the real issue.

Matthias
Logged
giorgiomx

Offline Offline

Posts: 11


« Reply #3 on: February 02, 2008, 01:35:59 AM »

Hello,

1.) Please use the latest version of WB (2.6.7) and the FCKEditor (2.81). All described issues from WB in the link from RedGnomos are only in earlier versions (see the dates are all befor 2007) and fixed in the actually version.

2.) All pages wich was hacked, was hacked on unsecure servers. To overwrite the config.php or the index.php can only be done from a hacker wich has full access to the server. This is not possible through WB. So please ask your hoster for the server logs. There you will see when and how the files are changed. I'm pretty shure you will not got this infos from your hoster as he will recognize in these logfiles that his server config is the real issue.

Matthias

Hi

So far...
They told me the folders which have 777 are not secure and that's why a shell script was uploaded on /media folder.
They deleted the script and told me to change folder permissions.

WB needs these folders to have 777 permissions right? or is there a setting more secure that lets WB work.

Maybe is just an unsecure configuration I have on the WB installation

I really doubt is a server problem, I've been with them for more than 5 years and they're good and respectable company.
Sites without WB weren't hacked.
On one of those sites I clicked to edit a page, then on "manage sections" and instead of showing me the right options it showed an interfase to execute a lot of things, from an "Emperor" company/hacker or something.

I'll check the post you mention.
But, if the permissions are the problem and WB needs those permissions..., we have a problem.

Salutes

Giorgio
Logged
doc
Guest
« Reply #4 on: February 02, 2008, 10:16:45 AM »

Hello,

well all users you trust and have access to the media directory are able to upload files via the WB backend.
With FCKEditor < 2.75 even users without access to the backend were able to upload files to the media directory call them via the URL. This security vulnerability was reported in the board Security Announcement the same day we were informed about this issue. Other Editors like Xinha, TinyMCE are affected as well.

So with a WB standalone installation, no security vulnerabilities are reported since 2.6.5.
If you have an older FCK version or an WYSIWYG edior other than HTMLArea, please update as soon as possible to the latest FCKEditor version available on the Addons repository.

So I am sure, it is not a WB related problem, it may be a problem with one of the WYSIWYG editor addons.

Regards Christian

« Last Edit: February 02, 2008, 10:19:36 AM by doc » Logged
giorgiomx

Offline Offline

Posts: 11


« Reply #5 on: February 03, 2008, 08:50:49 PM »

In a moment I'm going to start the updates and stuff for the sites...

One question:
In order for WB to work, folders don't have to be 777?

thank you

Giorgio
Logged
albatros

Offline Offline

Posts: 674


WWW
« Reply #6 on: February 03, 2008, 10:25:42 PM »

Hi Giorgio,

have a look at the excellent help-projct please, especially here:
http://help.websitebaker.org/pages/en/basic-docu/installation/wb-installer.php

hth

albatros
« Last Edit: February 03, 2008, 10:27:30 PM by albatros » Logged
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!