PEAK XOOPS - probablly site hijacked because of myalbum in englishin japanese

probablly site hijacked because of myalbum

  • You cannot open a new topic into this forum
  • Guests cannot post into this forum
Previous post - Next post | Parent - Children.1 .2 .3 .4 .5 | Posted on 2008/7/14 1:04
marckd  办霹始   Posts: 18
hello everybody

recently my site was hijacked, a couple of files have been uploaded and modified, and the only thing I can think about it, is that somehow they upload it through myalbum, as it is the only thing available to upload files in my site

my firewall haven't detected anything

is there a known bug or something for myalbum version 2.86 with xoops 2.0.14 ?

thanks for your time
Votes:4 Average:7.50
Previous post - Next post | Parent - No child | Posted on 2008/7/14 12:34 | Last modified
GIJOE  黎扦烦菱   Posts: 4110
hi marckd.

Have you enabled Protector?
It's a MUST module for the core from xoops.org like 2.0.14

And myAlbum-P always checks the uploaded files are valid or not.

Anyway, show the file to me with detail if you doubt me.
Votes:0 Average:0.00
Previous post - Next post | Parent - Children.1 | Posted on 2008/7/15 14:42
marckd  办霹始   Posts: 18
thanks for the soon reply!

Protector? what is that and where do I enable it?

I know and I really trust about myAlbum, it is by far my most favourite module in xoops, but due to this hack, google penalized me and my visits dropped 70% in just one day, and yet I can't understand where they got access, this was the only way to upload files, and so my first thought about the hack

sorry if I offended you, it wasn't my intention, just to find out how they got access and to be preventive for the future

thanks again
Votes:0 Average:0.00
Previous post - Next post | Parent - No child | Posted on 2008/7/15 22:27
stranger  惧霹始   Posts: 22
Votes:1 Average:0.00
Previous post - Next post | Parent - No child | Posted on 2008/7/16 3:17
GIJOE  黎扦烦菱   Posts: 4110
hi marckd.

Don't call cracker == "script kiddie" as "Hacker" please.
Hacker is a honorific title.

And my module is named myAlbum-P instead of "myAlbum".

Quote:

Protector? what is that and where do I enable it?
sigh...

Quote:
this was the only way to upload files, and so my first thought about the hack
You should know, a cracker can make files as he like via some vulnerable codes.
The feature of uploading is unrelated.

And, myAlbum-P always put uploaded files (number).(ext) like 1.jpg

You should check all modules you use.

In fact, There are too many vulnerable modules in xoops.org
Votes:0 Average:0.00
Previous post - Next post | Parent - Children.1 | Posted on 2008/7/16 4:54
marckd  办霹始   Posts: 18
0k, sorry again for the wrong terms

Quote:
In fact, There are too many vulnerable modules in xoops.org
is there a way to know this? a list maybe or some way to check vulnerabilities?

thanks again
Votes:0 Average:0.00
Previous post - Next post | Parent - No child | Posted on 2008/7/18 5:01
GIJOE  黎扦烦菱   Posts: 4110
Quote:

Quote:
In fact, There are too many vulnerable modules in xoops.org
is there a way to know this? a list maybe or some way to check vulnerabilities?
Only skilled programmers/hackers can do that.
As far as I know, all code checkers for PHP are useless.
Votes:2 Average:5.00
Previous post - Next post | Parent - No child | Posted on 2008/7/21 3:15
marckd  办霹始   Posts: 18
0k! thanks for your time GIJOE :)
Votes:3 Average:6.67

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!