Home Private Messages Search
CPG Dragonflyâ„¢ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Account Suspended due to Spamming :: Archived


Account Suspended due to Spamming :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
RFJ_Pony97
Newbie
Newbie

Offline Offline
Joined: Aug 02, 2004
Posts: 7
Location: Chicago
PostPosted: Thu May 18, 2006 1:21 pm
Post subject: Account Suspended due to Spamming

My server account has been suspended due to someone getting in and using it to spam. They say I can't have the site back until I give them a plan on how I'm going to stop this. Well I have no idea what to tell them. Any help would be appreciated.


RFJ_Pony97's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/?/4.3.8/4.0.20/9.0.6.1
Back to top
View user's profile Visit poster's website
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Thu May 18, 2006 4:57 pm
Post subject: Re: Account Suspended due to Spamming

I have a question, how is this dragonflycms related?

_________________
iPad 1

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
RFJ_Pony97
Newbie
Newbie

Offline Offline
Joined: Aug 02, 2004
Posts: 7
Location: Chicago
PostPosted: Fri May 19, 2006 1:15 pm
Post subject: Re: Account Suspended due to Spamming

Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS.


RFJ_Pony97's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/?/4.3.8/4.0.20/9.0.6.1
Back to top
View user's profile Visit poster's website
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Fri May 19, 2006 1:23 pm
Post subject: Re: Account Suspended due to Spamming

RFJ_Pony97 wrote:
Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS.

Floor laughing
Thats funny.
Your provider needs to wake up. DF is the most secure CMS out there. Sounds like your providers sever isnt secure on the smtp end. Try to send out an email using mail.yoursite.xxx without a password. I bet it will work.

I host almost nothing but DF sites on 5 servers and I don't allow phpnuke or postnuke because of security issues that have almost brought my servers down. Ive NEVER had any issues with this wonderful CMS.

_________________
iPad 1

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Fri May 19, 2006 1:25 pm
Post subject: Re: Account Suspended due to Spamming

SBN-WEB-HOSTING.COM
Is that your host?
I think they have some bad issues themselves. I'd look for another host, fast.


bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Fri May 19, 2006 2:16 pm
Post subject: Re: Account Suspended due to Spamming

RFJ_Pony97 wrote:
give them a plan on how I'm going to stop this
Try changing your passwords and be sure to use strong password that includes number digits, capital and lower cases.

Also make sure to enable ssl (or any other way to secure your connection) to smpt, pop3 and other tools authentification (ask your provider about this), otherwise you will send a plain password.

Let them know that you are using a secure, stable and optimized cms. Maybe they should ask all other users to use Dragonfly!

This is a start point to fix your/their problem, we all never experienced similar episodes.

If you/they cannot found a solution I'll invite you to change cms to probably have the same problem, an higher server load and maybe an hacked database.

All i know about spam: they filled up my inbox with 1500+ emails, they used my account (and others) to spam emails but in less then 24 hours my provider fixed the problem with some software updates.

I'm not probably the best that could help you and your provider but using using some basics for security, strong passwords, encrypted connections and software and services updates will not be that bad for sure.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Fri May 19, 2006 3:09 pm
Post subject: Re: Account Suspended due to Spamming

RFJ_Pony97 wrote:
Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS.

I dont'know if that spamming could be somehow related to the following but do you update your cms with the latest security patches? It was announced some time ago through the update monitor that four files were improved on security. Of course you need to have the monitor enabled or watch the security forums to know.

And which cms did you or your host think was more secure than Dragonfly?

Dragonfly is not PHP-Nuke, even if it was derived from it long ago and was once called CPG-Nuke.


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
Gallowglas
Nice poster
Nice poster

Offline Offline
Joined: Nov 13, 2004
Posts: 89
Location: Germany
PostPosted: Fri May 19, 2006 3:38 pm
Post subject: Re: Account Suspended due to Spamming

bigern75 wrote:


Floor laughing
Thats funny.
Your provider needs to wake up. DF is the most secure CMS out there. Sounds like your providers sever isnt secure on the smtp end. Try to send out an email using mail.yoursite.xxx without a password. I bet it will work.

Well, they don ´t even need to use the server for spamming ...
Some years ago I registered a domain at a local provider (1 domain was free :-)) and never used it in any way ( catchall mails are forwarded to my normal mailaccount, but thats it) .. but from time to time i get loads of spamreports, saying my domain was used to spam .. so what, it ´s easy to fake the FROM: ...


Gallowglas's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.37/4.0.25-5.0.18/4.4.7-5.2.1/9.0.6.1-9.1.2.5
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Fri May 19, 2006 3:44 pm
Post subject: Re: Account Suspended due to Spamming

Quote::
easy to fake the FROM: ...
thats correct

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Fri May 19, 2006 4:06 pm
Post subject: Re: Account Suspended due to Spamming

If you check the header and the queue, it will show it went thru the account. And thats how they know it was using that account. Even if they fake the FROM: You can actually see which accounts smtp it went thru.

I truely dont see this being a DF issue.

_________________
iPad 1

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Fri May 19, 2006 7:15 pm
Post subject: Re: Account Suspended due to Spamming

Don't be so quick to condemn - it could easily be a dragonfly issue for a variety of reasons, like failure to adopt security updates, use of insecure modules (plenty of them around), poor password control.

I guess it's a moot point now, but a host does need to give you some info to go with before ASSuming was Dragonfly security was the issue.


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
bigern75
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 18, 2004
Posts: 2102
Location: River Valley - FS AR
PostPosted: Fri May 19, 2006 7:21 pm
Post subject: Re: Account Suspended due to Spamming

RFJ_Pony97, could you please give us a little more info to go on.
Thanks Smile

_________________
iPad 1

bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.6/5.0.86/5.2.8/9.3.2
Back to top
View user's profile Visit poster's website
ofigustavo
Nice poster
Nice poster

Offline Offline
Joined: Aug 21, 2005
Posts: 109
Location: Canary Islands-Spain
PostPosted: Fri May 19, 2006 7:32 pm
Post subject: Re: Account Suspended due to Spamming

Floor laughing

I advise you to change to another host supplier. More serious and intelligent.Do they know what is a CMS ?With another CMS? Like phpnuke,for example? Floor laughing


best regards


ofigustavo please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Fri May 19, 2006 7:36 pm
Post subject: Re: Account Suspended due to Spamming

Don't laugh too loud - Dragonfly has its moments, albeit very brief moments, thanks to DJ and Syama_Dasa's response to security issues.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Fri Jun 02, 2006 1:15 pm
Post subject: Re: Account Suspended due to Spamming

looks like he's moved to joomla.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

lexo me teper

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy