![]() |
|
Virus hacks--Warning!!! - Printable Version +- ZenphotoCMS Forum (https://forum.zenphoto.org) +-- Forum: Support (https://forum.zenphoto.org/forum-1.html) +--- Forum: General support (https://forum.zenphoto.org/forum-4.html) +--- Thread: Virus hacks--Warning!!! (/thread-9227.html) |
Virus hacks--Warning!!! - acrylian - 2011-11-10 As said it might be that all these hacks are coincidence and not even related. We don't know. It is always possible that someone hacked into the server itself (and not just your webspace if on shared host). That happens occasionally even on major hosts (a few weeks to a German one if I recall right). Also a hacked computer system or infected browser and numerous other things could be involved. Or third party scripts like analytics or ads maybe a way, too. Best contact your provider if you have suspicion that happened. Virus hacks--Warning!!! - acrylian - 2011-11-10 @huscste: To check if the db has been corrupt you can only do one thing: Look into it.. Virus hacks--Warning!!! - hucste - 2011-11-10 @acrylin: i've contacted my webprovider to inform-it. For my datas, it's not a very big problem... Virus hacks--Warning!!! - paintscape - 2011-11-10 I would like to know if this security issue effects older versions such as 1.26? Does anyone know if that is the case? Virus hacks--Warning!!! - acrylian - 2011-11-10 No need to double post. Anyway, the 2nd security alert article has now that info. Bascically all release since 1.2.4 include the file manager was first used by the Zenpage CMS plugin only. The plugin itself existed independently since Zenphoto 1.2.1. This makes me think the hacks maybe are not directly related to the file mananager. Nevertheless the deletion is a good idea. Virus hacks--Warning!!! - hucste - 2011-11-10 hi @acrylian... perhaps, it's preferable to create a new archive that contains the ultime version + the tinymce replacements. no?! Virus hacks--Warning!!! - helfgott - 2011-11-10 Hi people i've been hacked through that security hole in tiny_mce: 92.63.104.34 - - [09/Nov/2011:07:57:00 -0300] "POST /zenphoto/zp-core/zp-extensions/tiny_mce/plugins/ajaxfilemanager/inc/class.images.php?truecss=1 HTTP/1.1" 200 181 "-" "User-Agent: Mozilla/5.0 (Windows; u; Windows nt 5.1; en-us; rv:1.9.1.5) gecko/20091102 firefox/3.5.5 gtb5" 82.146.43.62 - - [09/Nov/2011:18:28:38 -0300] "POST /zenphoto/zp-core/zp-extensions/tiny_mce/plugins/ajaxfilemanager/inc/class.images.php?truecss=1 HTTP/1.1" 200 181 "-" "User-Agent: Mozilla/5.0 (Windows; u; Windows nt 5.1; en-us; rv:1.9.1.5) gecko/20091102 firefox/3.5.5 gtb5" I had several POST attacks (it allows to upload files as i saw in (devilscoffee) They've changed every single .php /.js files with a malicious code. Also they've reach the .htaccess file and added some crazy rules to redirect. Now i'm flagged by google, that hole killed my wordpress, joomla, zencart and zenphoto installations. Now i'm trying to get back with all, this is a huge whole. Virus hacks--Warning!!! - jest3r- - 2011-11-10 Here is what seems to be happening.
What to do about it? How to fix it?
If you don't have a backup you will need to delete Zen Photo completely a reinstall (make sure you delete the ajaxfilemanager directory if you reinstall)
Run these commands from the top directory on your server or hosting account: This will show you all the files on your webserver that have been infected and need to be cleaned: grep -r -H "lb11" * (looks for the string 'lb11' in every file - infected files have this inserted into them) You can substitute 'lb11' with other strongs that the hacker might have inserted into your code. For example: grep -r -H "eval(base64_decode" * Use the find command to show additional files that may have been installed on your server: find / -name tmp* Use the find command to show files that have been modified in the last day (these would be the files that have been infected or added): find . -type f -mtime -1 Look in your access log files for suspicious activity and Ban those IP addresses: cat access.log | grep ajaxfilemanager Hope this info helps ... Virus hacks--Warning!!! - acrylian - 2011-11-10 Thanks, that is a great analysis. I will link that on our news section. Virus hacks--Warning!!! - acrylian - 2011-11-10 @hucste: Quote:perhaps, it's preferable to create a new archive that contains the ultime version + the tinymce replacements. no?! The 1.4.2 beta nightly of the coming night at least will have the fix. Virus hacks--Warning!!! - hucste - 2011-11-10 Thanks jest3r- : about the point 5, also, if you can change BD user ... do-it ! Virus hacks--Warning!!! - bic - 2011-11-10 Ok, thanks jest3r-, good idea to change the database password too. My provider says that there is not such a risk, but it souds strange to me. I've some minor issues, as always after a long time needed update, but I'll deal with them later on. Virus hacks--Warning!!! - jest3r- - 2011-11-10 bic: if their exploit can infect every file on your server that means it can read those files too. Typically what happens is a robot scans millions of websites and when it finds a vulnerability it "quietly" creates a backdoor and notifies whomever is running the robot. If that person then follows up .. perhaps a few days later ... they will have access to your files. That's why the damage reports are so different from everyone. Depends on what stage of the "attack" you are in. They wouldn't be able to get your FTP password ... but the config files all contain your database passwords in plain text which is readable by the hacker on an infected website. So change your passwords!! Virus hacks--Warning!!! - bic - 2011-11-10 Thanks again jest3r-, For people with custom themes: Virus hacks--Warning!!! - mikeque - 2011-11-10 Do the latest builds from last night include this fix? Virus hacks--Warning!!! - acrylian - 2011-11-10 No, tonights will. But caution that nightly is now 1.4.2 beta (as announced some days ago). Since a few things change you might run into trouble. Just replace the tiny_mce plugin with the one now provided on the post (and download page) or remove it yourself. Virus hacks--Warning!!! - kilroy - 2011-11-11 Vulnerable websites are apparently found using this search in Google: Here is a page showing how to find and hack vulnerable websites. Part of the problem is due to Google who managed to find and index these paths (the question is how?). Virus hacks--Warning!!! - acrylian - 2011-11-11 The good search engine crawlers respect those setting but I am not convince those with bad intentions do as well. I think that with the right permissions these directories should not be indexable at all. Virus hacks--Warning!!! - hucste - 2011-11-11 Another attention, please, with this hack, it's possible to upload image .jpg... and by this way, it's possible to obtain control to the visitor station, if a potentially victim download this image modified. In fact, not considere that yours albums are clean! Prefere delete all ... and after reinstall zenphoto with 1.4.1.6, upload yours images jpg - thoses are you sure that cleaned, protected. PS : excuse-me for my very poor english... Virus hacks--Warning!!! - acrylian - 2011-11-11 Good point. Btw, your English is for sure better than my French..;-) |