| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
RFJ_Pony97 Newbie


Offline Joined: Aug 02, 2004 Posts: 7 Location: Chicago
|
Posted: Thu May 18, 2006 1:21 pm Post subject: Account Suspended due to Spamming |
|
My server account has been suspended due to someone getting in and using it to spam. They say I can't have the site back until I give them a plan on how I'm going to stop this. Well I have no idea what to tell them. Any help would be appreciated.
RFJ_Pony97's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/?/4.3.8/4.0.20/9.0.6.1
|
|
| Back to top |
|
 |
bigern75 Platinum Supporter


Offline Joined: Aug 18, 2004 Posts: 2102 Location: River Valley - FS AR
|
Posted: Thu May 18, 2006 4:57 pm Post subject: Re: Account Suspended due to Spamming |
|
I have a question, how is this dragonflycms related?
_________________ iPad 1
bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/2.2.6/5.0.86/5.2.8/9.3.2
|
|
| Back to top |
|
 |
RFJ_Pony97 Newbie


Offline Joined: Aug 02, 2004 Posts: 7 Location: Chicago
|
Posted: Fri May 19, 2006 1:15 pm Post subject: Re: Account Suspended due to Spamming |
|
Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS.
RFJ_Pony97's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/?/4.3.8/4.0.20/9.0.6.1
|
|
| Back to top |
|
 |
bigern75 Platinum Supporter


Offline Joined: Aug 18, 2004 Posts: 2102 Location: River Valley - FS AR
|
Posted: Fri May 19, 2006 1:23 pm Post subject: Re: Account Suspended due to Spamming |
|
| RFJ_Pony97 wrote: |
| Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS. |
Thats funny.
Your provider needs to wake up. DF is the most secure CMS out there. Sounds like your providers sever isnt secure on the smtp end. Try to send out an email using mail.yoursite.xxx without a password. I bet it will work.
I host almost nothing but DF sites on 5 servers and I don't allow phpnuke or postnuke because of security issues that have almost brought my servers down. Ive NEVER had any issues with this wonderful CMS.
_________________ iPad 1
bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/2.2.6/5.0.86/5.2.8/9.3.2
|
|
| Back to top |
|
 |
bigern75 Platinum Supporter


Offline Joined: Aug 18, 2004 Posts: 2102 Location: River Valley - FS AR
|
Posted: Fri May 19, 2006 1:25 pm Post subject: Re: Account Suspended due to Spamming |
|
SBN-WEB-HOSTING.COM
Is that your host?
I think they have some bad issues themselves. I'd look for another host, fast.
bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/2.2.6/5.0.86/5.2.8/9.3.2
|
|
| Back to top |
|
 |
NanoCaiordo Developer


Offline Joined: Jun 29, 2004 Posts: 3878 Location: Melbourne, AU
|
Posted: Fri May 19, 2006 2:16 pm Post subject: Re: Account Suspended due to Spamming |
|
| RFJ_Pony97 wrote: |
| give them a plan on how I'm going to stop this |
Try changing your passwords and be sure to use strong password that includes number digits, capital and lower cases.
Also make sure to enable ssl (or any other way to secure your connection) to smpt, pop3 and other tools authentification (ask your provider about this), otherwise you will send a plain password.
Let them know that you are using a secure, stable and optimized cms. Maybe they should ask all other users to use Dragonfly!
This is a start point to fix your/their problem, we all never experienced similar episodes.
If you/they cannot found a solution I'll invite you to change cms to probably have the same problem, an higher server load and maybe an hacked database.
All i know about spam: they filled up my inbox with 1500+ emails, they used my account (and others) to spam emails but in less then 24 hours my provider fixed the problem with some software updates.
I'm not probably the best that could help you and your provider but using using some basics for security, strong passwords, encrypted connections and software and services updates will not be that bad for sure.
_________________ .:: I met php the 03 December 2003 :: Unforgettable day! ::.
Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) mixed
|
|
| Back to top |
|
 |
alva 1000+ Posts Club


Offline Joined: May 31, 2005 Posts: 1150 Location: The Netherlands
|
Posted: Fri May 19, 2006 3:09 pm Post subject: Re: Account Suspended due to Spamming |
|
| RFJ_Pony97 wrote: |
| Because the server provider told me that the exploit probably came through Dragonfly and has told me to use another CMS. So I guess it doesn't really matter, since I will be dropping this CMS. |
I dont'know if that spamming could be somehow related to the following but do you update your cms with the latest security patches? It was announced some time ago through the update monitor that four files were improved on security. Of course you need to have the monitor enabled or watch the security forums to know.
And which cms did you or your host think was more secure than Dragonfly?
Dragonfly is not PHP-Nuke, even if it was derived from it long ago and was once called CPG-Nuke.
alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache/5.0.24/5/9.1 CVS
|
|
| Back to top |
|
 |
Gallowglas Nice poster


Offline Joined: Nov 13, 2004 Posts: 89 Location: Germany
|
Posted: Fri May 19, 2006 3:38 pm Post subject: Re: Account Suspended due to Spamming |
|
| bigern75 wrote: |
Thats funny.
Your provider needs to wake up. DF is the most secure CMS out there. Sounds like your providers sever isnt secure on the smtp end. Try to send out an email using mail.yoursite.xxx without a password. I bet it will work. |
Well, they don ´t even need to use the server for spamming ...
Some years ago I registered a domain at a local provider (1 domain was free :-)) and never used it in any way ( catchall mails are forwarded to my normal mailaccount, but thats it) .. but from time to time i get loads of spamreports, saying my domain was used to spam .. so what, it ´s easy to fake the FROM: ...
Gallowglas's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.37/4.0.25-5.0.18/4.4.7-5.2.1/9.0.6.1-9.1.2.5
|
|
| Back to top |
|
 |
NanoCaiordo Developer


Offline Joined: Jun 29, 2004 Posts: 3878 Location: Melbourne, AU
|
Posted: Fri May 19, 2006 3:44 pm Post subject: Re: Account Suspended due to Spamming |
|
| Quote:: |
| easy to fake the FROM: ... |
thats correct
_________________ .:: I met php the 03 December 2003 :: Unforgettable day! ::.
Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) mixed
|
|
| Back to top |
|
 |
bigern75 Platinum Supporter


Offline Joined: Aug 18, 2004 Posts: 2102 Location: River Valley - FS AR
|
Posted: Fri May 19, 2006 4:06 pm Post subject: Re: Account Suspended due to Spamming |
|
If you check the header and the queue, it will show it went thru the account. And thats how they know it was using that account. Even if they fake the FROM: You can actually see which accounts smtp it went thru.
I truely dont see this being a DF issue.
_________________ iPad 1
bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/2.2.6/5.0.86/5.2.8/9.3.2
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Fri May 19, 2006 7:15 pm Post subject: Re: Account Suspended due to Spamming |
|
Don't be so quick to condemn - it could easily be a dragonfly issue for a variety of reasons, like failure to adopt security updates, use of insecure modules (plenty of them around), poor password control.
I guess it's a moot point now, but a host does need to give you some info to go with before ASSuming was Dragonfly security was the issue.
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
bigern75 Platinum Supporter


Offline Joined: Aug 18, 2004 Posts: 2102 Location: River Valley - FS AR
|
Posted: Fri May 19, 2006 7:21 pm Post subject: Re: Account Suspended due to Spamming |
|
RFJ_Pony97, could you please give us a little more info to go on.
Thanks
_________________ iPad 1
bigern75's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/2.2.6/5.0.86/5.2.8/9.3.2
|
|
| Back to top |
|
 |
ofigustavo Nice poster


Offline Joined: Aug 21, 2005 Posts: 109 Location: Canary Islands-Spain
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Fri May 19, 2006 7:36 pm Post subject: Re: Account Suspended due to Spamming |
|
Don't laugh too loud - Dragonfly has its moments, albeit very brief moments, thanks to DJ and Syama_Dasa's response to security issues.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
djdevon3 Gold Supporter


Offline Joined: Aug 05, 2004 Posts: 4363
|
Posted: Fri Jun 02, 2006 1:15 pm Post subject: Re: Account Suspended due to Spamming |
|
looks like he's moved to joomla.
djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/1.3.33/4.4/4.3.11
|
|
| Back to top |
|
 |
|
|