Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ Hacked! :: Archived


Hacked! :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page Previous  1, 2
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Tue Sep 05, 2006 9:05 pm
Post subject: Re: Hacked!

The mentioned Stokia article says it was a Windows/IIS issue. RottGutt is on Linux/Apache.


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
Jordo
Newbie
Newbie

Offline Offline
Joined: Jan 31, 2005
Posts: 27

PostPosted: Tue Sep 05, 2006 9:15 pm
Post subject: Re: Hacked!

Right... I had updated my last post to the fact that it was probably his hosting service.

There's a pretty big thread at Lunarpages with a bunch of sites that were hacked yesterday on a couple of their servers.

_________________
Jordo
www.jordomedia.com

Jordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.0.22/4.3.10/9.0.3
Back to top
View user's profile Visit poster's website
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Tue Sep 05, 2006 9:48 pm
Post subject: Re: Hacked!

Not a DF issue then and this can be locked/moved.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
RottGutt
Heavy poster
Heavy poster

Offline Offline
Joined: Feb 24, 2005
Posts: 281
Location: Colorado Springs, CO
PostPosted: Wed Sep 06, 2006 12:22 am
Post subject: Re: Hacked!

After looking at the Lunarpages.com forum thread about this issue I want to officially take back my original statement about the security of the DragonFly CMS. My apologies on my obvious premature statement.

Tim


RottGutt's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux OS/Apache v1.3.34/MySQL v4.0.25-Standard/PHP v4.4.1/CPGNuke v9.0.6.1
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Wed Sep 06, 2006 12:26 am
Post subject: Re: Hacked!

No problem - you had to assume the worst Smile

Regrettably it's one of the problems that goes with shared servers, which is why we are also cautious in accepting Dragonfly is the cause on a shared server.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Wed Sep 06, 2006 1:08 am
Post subject: Re: Hacked!

i would dump that host in a hurry

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
scetter
Nice poster
Nice poster

Offline Offline
Joined: Oct 12, 2005
Posts: 127

PostPosted: Sat Sep 16, 2006 8:23 am
Post subject: Re: Hacked!

Dizfunkshunal wrote:
i would dump that host in a hurry

Seems always that is the answer. But it also seems that all servers have some kind of vulnerability.
Take this sight as an example.

It's not a matter of which host but when it will happen.

I'm sure most hosts do all they can to work on security, why would they want their servers hacked? It makes their job harder too.

You could very easily get hacked through someone elses site on a shared server. If one person on a shared surver is insecure then it makes all the other site insecure.

Neutral

_________________
Scetter.com

scetter's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.20/5.1.61-log/5.3.8/9.3.3.1
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Sat Sep 16, 2006 9:33 am
Post subject: Re: Hacked!

RottGutt wrote:
After looking at the Lunarpages.com forum thread about this issue I want to officially take back my original statement about the security of the DragonFly CMS. My apologies on my obvious premature statement.

Tim

End of this thread Smile


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page    Forum Index ⇒  Security
Page 2 of 2
All times are GMT
Go to page Previous  1, 2

 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy