Server hacked :: Archived Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com Do Not post links to exploits or hacker sites - your post will be edited/deleted. If you think you've been hacked, FIRST go through your server logs. Go to page Previous1, 2
Posted: Wed Nov 16, 2005 9:52 pm Post subject: Re: Server hacked
Most current php security vulnerabilities including overloading is stopped by Dragonfly.
However Dragonfly will not report them since there's no 100% secure check wether it's an exploit script or just some dumb visitor typing wrong data.
There's also another kind of exploit in php/apache that will go around Dragonfly since they are performed before Dragonfly gets executed.
To prevent version sniffing Dragonfly overwrites the "X-Powered" header but it can't overwrite the "Server" header tag (which is something your host should do thru httpd.conf)
Most worms and trojans are injected thru vulnerabilities in any program. As far as we know there are no known vulnerabilities in Dragonfly other then in PHP itself.
So yes it would be best to check security updates for those as mentioned by Akamu.
DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS