Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Hacked! :: Archived


Hacked! :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
RottGutt
Heavy poster
Heavy poster

Offline Offline
Joined: Feb 24, 2005
Posts: 281
Location: Colorado Springs, CO
PostPosted: Mon Sep 04, 2006 11:25 pm
Post subject: Hacked!

I don't know what else to say about this. There was NO transfer of information to any outside party. When I logged onto my WoW site tonight I got this:

So much for CPG-Nuke being secure!


RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
Back to top
View user's profile Visit poster's website
NEMINI
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Apr 22, 2004
Posts: 4551

PostPosted: Mon Sep 04, 2006 11:43 pm
Post subject: Re: Hacked!

do you have ANY prrof that it was through cpgnuke that you got hacked? Just because you run cpgnuke and got hacked does not make it cpgnukes fault.

_________________
NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org

NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website Photo Gallery
RottGutt
Heavy poster
Heavy poster

Offline Offline
Joined: Feb 24, 2005
Posts: 281
Location: Colorado Springs, CO
PostPosted: Mon Sep 04, 2006 11:49 pm
Post subject: Re: Hacked!

NEMINI wrote:
do you have ANY prrof that it was through cpgnuke that you got hacked? Just because you run cpgnuke and got hacked does not make it cpgnukes fault.

I don't exactly know how to prove it. I have the site's raw access logs that I will go through. The only access to the site was through the Internet, nobody has accessed it through FTP or any other method in 3 weeks. I believe that in this case that we need to consider CPG-Nuke unsecure to some new access method until it is deemed not true. Unfortunately, I do not have the knowledge on what exactly to do to trace the source of the hack. I have changed the domain's password, erased my public_html folder, and will be re-installing CPG-Nuke tonight. We shall see what happens...


RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
Back to top
View user's profile Visit poster's website
NEMINI
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Apr 22, 2004
Posts: 4551

PostPosted: Mon Sep 04, 2006 11:50 pm
Post subject: Re: Hacked!

you on a shared box? dedicated? self run?

_________________
NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org

NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website Photo Gallery
RottGutt
Heavy poster
Heavy poster

Offline Offline
Joined: Feb 24, 2005
Posts: 281
Location: Colorado Springs, CO
PostPosted: Mon Sep 04, 2006 11:58 pm
Post subject: Re: Hacked!

NEMINI wrote:
you on a shared box? dedicated? self run?

Shared box on LunarPages.com. I have already submitted a trouble ticket asking them to trace the source of the attack and press charges. I have also asked them to do a restore of the site with their latest backup.


RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
Back to top
View user's profile Visit poster's website
NEMINI
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Apr 22, 2004
Posts: 4551

PostPosted: Tue Sep 05, 2006 12:02 am
Post subject: Re: Hacked!

it's at least as possible someone else on the same server could have been compromised leading to you being hacked as cpgnuke being responsible.

Until more is known anything is possible.

PS: did you patch the known search exploit?

_________________
NEMINI.org, NEMINI.us, NEMINI.info, NYMINI.org

NEMINI's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
1.3.34 (Unix)/4.1.18-standard/4.4.2 /9.1.0.8 CVS
Back to top
View user's profile Visit poster's website Photo Gallery
masterbeta
Translator
Translator

Offline Offline
Joined: May 12, 2004
Posts: 1049
Location: Reading, PA
PostPosted: Tue Sep 05, 2006 12:04 am
Post subject: Re: Hacked!

sounds as if lunarpages' server was hacked - not specifically cpg-nuke as your target.

_________________
[]D [] []\/[] []D
Check out my bear site - www.insidebear.com

masterbeta's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
RHL7 2.6.9-67.0.15ELsmp/A1.3.41(Unix)/MySQL4.1.22-standard/PHP5.2.5-ZO/Dragonfly 9.1.2.1
Back to top
View user's profile Visit poster's website
RottGutt
Heavy poster
Heavy poster

Offline Offline
Joined: Feb 24, 2005
Posts: 281
Location: Colorado Springs, CO
PostPosted: Tue Sep 05, 2006 12:41 am
Post subject: Re: Hacked!

NEMINI wrote:
it's at least as possible someone else on the same server could have been compromised leading to you being hacked as cpgnuke being responsible.

Until more is known anything is possible.

PS: did you patch the known search exploit?

That is true. I would hope that they would honest enough to say if that was actually what happened. I will keep ya'll informed as I get new information. Yes, not only did I patch the known search exploit, but I also had all search features turned off on the site.


RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Tue Sep 05, 2006 1:59 am
Post subject: Re: Hacked!

it wasnt DF the hacker gained access to. theres no way the could change the entire page that way unless they had server access

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Tue Sep 05, 2006 12:08 pm
Post subject: Re: Hacked!

RottGutt wrote:
Yes, not only did I patch the known search exploit, but I also had all search features turned off on the site.
How about the other official 9.0.6.1 security patches? (Those are more important than the Search thingy as far as I know.)


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
RedRincon650
Nice poster
Nice poster

Offline Offline
Joined: Mar 09, 2006
Posts: 118
Location: Winnipeg Manitoba
PostPosted: Tue Sep 05, 2006 5:32 pm
Post subject: Re: Hacked!

You might find th is to be of some interest...

www.stokia.com/news/is...k-info.htm


RedRincon650's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache-2/MySQL-4/PHP-4/CMS-9.1RC2
Back to top
View user's profile Visit poster's website
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Tue Sep 05, 2006 5:43 pm
Post subject: Re: Hacked!

That is either the answer or someone using that issue as a coverup. Is lunarpages by chance a subsidiary of godaddy?


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Jordo
Newbie
Newbie

Offline Offline
Joined: Jan 31, 2005
Posts: 27

PostPosted: Tue Sep 05, 2006 6:56 pm
Post subject: Re: Hacked!

djdevon3 wrote:
That is either the answer or someone using that issue as a coverup. Is lunarpages by chance a subsidiary of godaddy?

No, but some people keep godaddy as their registrar, even if they host their sites somewhere else.

_________________
Jordo
www.jordomedia.com

Jordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.0.22/4.3.10/9.0.3
Back to top
View user's profile Visit poster's website
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Tue Sep 05, 2006 7:41 pm
Post subject: Re: Hacked!

Having godaddy as your registrar means nothing. The registrar was not hacked godaddy hosting was which is a seperate entity/system.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
Jordo
Newbie
Newbie

Offline Offline
Joined: Jan 31, 2005
Posts: 27

PostPosted: Tue Sep 05, 2006 8:06 pm
Post subject: Re: Hacked!

djdevon3 wrote:
Having godaddy as your registrar means nothing. The registrar was not hacked godaddy hosting was which is a seperate entity/system.

According to the article posted here, they were validating it by looking at the registrar. They are assuming that if the registrar is godaddy, then the site is hosted there. This isn't true and a bad assumption.

BUT, I haven't looked at any other articles to find a better written article.

<Edited to add the below>
And rereading the article, they are blaming it on an email script at Godaddy, So I went to the Lunarpages forum, and there's a thread there where multiple sites have been hacked.

Rottgutt,
If you haven't gotten a hold of lunarpages support, go to their forums, to find out the latest.

_________________
Jordo
www.jordomedia.com

Jordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.0.22/4.3.10/9.0.3
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy