July 27, 2008 | 09:38 PM  
Welcome

Don't have an account yet? You can create one, it is free, just click here

as a registered user you have some advantages like free downloads, comments and posting on our forums, depending upon this site's configuration and options.

 • •  Control Panel - Register - Login  • • 
Current Stable MDPro Lite 1.0821 Download
  Forum FAQForum FAQ   SearchSearch  UsergroupsUsergroups  PreferencesPreferences  Options forumOptions forum  Watched TopicsWatched Topics  Watched ForumsWatched Forums
Latest forum posts Latest forum posts  Log in to check your private messages Log in to check your private messages    Log inLog in 
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Author Message
mats0916
New MD user
New MD user


Joined: May 06, 2006
Posts: 10
Location: Canada
Member
Post  Posted: Jan 21, 2008 - 06:49 AM Reply with quote Back to top
Post subject: MDPro Lite 1.082 Hacked

Gents,

Not much activity in the forums nowadays. Since december I have had several attempts to get my site hacked. The first attempts were done on a 1.0.76 install. Last week I updated to 1.0.82 and today the site was hacked again. In all cases it seems the mySQL database had been compromised. As I can see the permissions at the site are set as they should. I have changed the db user and password and made sure md-config.php is encrypted and read only for others. My web hosting company is www.ixwebhosting.com.

What further measurements can be taken to secure an MDPro site? Is there any documentation about this? Overall I find the documentation for 1.0.8x a little bit lacking.

My site address is www.vdispatch.ca and information about the server can be found at www.vdispatch.ca/phpinfo.php

Thanks in advance for any help in this matter,
Mats Johansson

_________________
An expert is someone who learn more and more about less and less.
Eventually the expert will know everything about nothing.


Cheers,
Mats J
View user's profile Visit poster's website
mats0916
New MD user
New MD user


Joined: May 06, 2006
Posts: 10
Location: Canada
bannato
Post  Posted: Jan 21, 2008 - 07:10 AM Reply with quote Back to top

Oh and further one of the first things I did was to add the security fix 070917 (pnuserapi.php in Topics). It did not seem to help on the 1.0.76 installation and I do not know if this is needed for a 1.0.82 installation, I have not found anything in the docs.

_________________
An expert is someone who learn more and more about less and less.
Eventually the expert will know everything about nothing.


Cheers,
Mats J
View user's profile Visit poster's website
TiMax
Project Manager
Project Manager


Joined: July 31, 2003
Posts: 1552
Location: Quebec - Canada

Post  Posted: Jan 21, 2008 - 05:54 PM Reply with quote Back to top

What about your logs ?
NEVER install old fix, fix 070917 is an old fix for 1.076 .... if you install it in 1.082 maybe you can broke your installation
So, we need info's from your logs otherwise we can't help you

_________________
TiMaxMAX s.o.s.Fantasia e dinamicità Italiane, qualità e servizi Canadesi Web Services, hosting ed housing professionali
View user's profile Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
mats0916
New MD user
New MD user


Joined: May 06, 2006
Posts: 10
Location: Canada
bannato
Post  Posted: Jan 21, 2008 - 11:38 PM Reply with quote Back to top

TiMax,

Thanks for replying. After further investigations it turned out I got several mails from MDPro about hacking attempts (Sent to a mail box not forwarded...rerouted now). From those emails I gained the IP addresses (2 different) and blocked them from the site. It also looked like the admin user account was compromised (probably since my 1.0.76 installation) so I changed admin account and deleted the old one. Late yesterday evening I could see in my site logs both addresses were trying to get access again but were effectively 403'd. Let's see how good they are...

I have also deleted the pnuserapi.php fix. Thanks for the heads up.

Oh. And the abusing IP addresses has of course been reported to respective ISP.

_________________
An expert is someone who learn more and more about less and less.
Eventually the expert will know everything about nothing.


Cheers,
Mats J
View user's profile Visit poster's website
Display posts from previous:     
Jump to:  
All times are GMT + 13 Hours
Post new topic   Reply to topic
View previous topic Printable version Log in to check your private messages View next topic
Powered by MDForum 2.0.8© 2003-2007 MAXdev Team
Credits