Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Server hacked :: Archived


Server hacked :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 6:25 pm
Post subject: Server hacked

Showing up in my members online was a "blank" user. All registered users have names and my host confirmed this person logged in as Anonymous.

I've changed my $prefix & $user_prefix but not sure if this will stop them from getting in again?

They were running some sort of external script that pretty much crashed my server for a while. My host said "was like someone was trying to run some script on it and used up ALL the server's memory several times over...like a hundred times"

Is there anything else I can do to stop this?


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
NEMINI
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Apr 22, 2004
Posts: 4551

PostPosted: Tue Nov 08, 2005 6:38 pm
Post subject: Re: hacker logged in as Anonymous

a blank user does not necessarily mean a hacker ... its been discussed many a time ... its a sessions issue.

_________________
NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org

NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website Photo Gallery
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 6:52 pm
Post subject: Re: hacker logged in as Anonymous

Ok, I can agree to that, however when my host see's that our server is pretty much done for due to a script being run through/out of my portal and there's an blank user showing up in the members list and my stats tell me there's been over 900 MB of something going on by an "other/anonymous" login.. kinda makes me wonder Smile


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
NEMINI
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Apr 22, 2004
Posts: 4551

PostPosted: Tue Nov 08, 2005 6:54 pm
Post subject: Re: hacker logged in as Anonymous

check your server logs to see who that latest visitors are and run the IP's and see if they turn up anything interesting.

_________________
NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org

NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website Photo Gallery
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 7:13 pm
Post subject: Re: hacker logged in as Anonymous

Found the culprit in Macedonia - DDOS attack used my site as server entry point to put a script (udp.pl) on the server. Filter is in place to stop that particular script again.


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
dormouse
Newbie
Newbie

Offline Offline
Joined: Aug 31, 2005
Posts: 37

PostPosted: Tue Nov 08, 2005 10:43 pm
Post subject: Re: hacker logged in as Anonymous

Is this a Dragonfly issue?


dormouse's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.39/4.1.22/4.4.7/9.2.0
Back to top
View user's profile Visit poster's website
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 10:53 pm
Post subject: Re: hacker logged in as Anonymous

It was my dragonfly issue only due to the fact that I wasn't aware that I needed to change the $prefix & $user_prefix during install until I started searching through security info around here today. So now I'm trying to work out problems after changing those.


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Nov 08, 2005 10:59 pm
Post subject: Re: hacker logged in as Anonymous

Doesn't make sense - DDOS shouldn't get your site hacked, just severely slowed down. They can't even brute force your admin password unless they guess it within 5 attempts.

It does depend on what non-core Dragonfly "add-ons" you have.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Śyama_Dāsa
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2048
Location: Dragonfly CMS Tribe
PostPosted: Tue Nov 08, 2005 11:17 pm
Post subject: Re: hacker logged in as Anonymous

and what file did they find that udp.pl had been uploaded by?
have you seen this

_________________
AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM

Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 11:19 pm
Post subject: Re: hacker logged in as Anonymous

I hear what you're saying Phoenix, and I agree.. there didn't seem to be any damage done to my site. The problem being that the guy entered through my site - used my site as his doorway to the server.

Biggest question is where did he get in. Which is what brought me back here looking for security info and me coming across the $prefix changes.


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Nov 08, 2005 11:26 pm
Post subject: Re: Server hacked

It is just plain absurd - Anonymous cannot login, regardless of what you or your host may think.

"Our records do not indicate an existing user named Anonymous"

And a blank user gives you this,
"Our records do not indicate an existing user named"

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 11:39 pm
Post subject: Re: Server hacked

well.. I'm just saying what the server logs reported Phoenix, not out to start anything. I'm just trying to find out how to lock my site down or at least make it a whole lot harder for anyone to gain unauthorized entry.


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Nov 08, 2005 11:42 pm
Post subject: Re: Server hacked

Then perhaps you better read what Akamu posted and chase that up because that is the more likely cause.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
snowflake
Newbie
Newbie

Offline Offline
Joined: Jul 30, 2005
Posts: 29

PostPosted: Tue Nov 08, 2005 11:52 pm
Post subject: Re: Server hacked

sure thing


snowflake's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache 1.3.33 (Unix)/PHP 4.3.9/Dragonfly 9.0.6.0
Back to top
View user's profile Visit poster's website
Wide
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 07, 2004
Posts: 294
Location: Playa Del Rey, CA
PostPosted: Wed Nov 09, 2005 5:10 pm
Post subject: Re: Server hacked

Phoenix wrote:
Then perhaps you better read what Akamu posted and chase that up because that is the more likely cause.


Thats most likely the cause

There have been two (2) scripts going around targeting php vulnerabilites.
Yours has the tell tale signs of one of them.

Not a Dragonfly issue in my opinion Big grin


Wide's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian/Apache2/MySQL 4.1.15-Debian/PHP4 4.4.2-1build1/9.1.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy