Get XOOPS XOOPS FAQ Forums News Themes Modules
New Posts New Topics All Forums Index General Modules Themes Development International XOOPS.org

XOOPS vs. Herko Coomans

Make a donation

Please select an amount to donate


Do you want your username revealed with your donation?
Yes - List me as a Generous Donor
No - List my donation as from an Anonymous Donor


Search

Local Support Sites

Cumulus Tag Cloud

admin Arabic banner block Christmas comments cumulus DayDawn dhsoft e-Commerce E-Learning Google GUI hacks instant-zero jQuery module news Nordic Olédrion oxygen PageRank security SEO simple-XOOPS sport tag Theme wiki xoops

New Users

Registering user

# 96574

audriusr

Welcome to XOOPS!
XOOPS Code hosted on SourceForge


 Bottom   Previous Topic   Next Topic

1 2 »
#1 Posted on: 2005/1/28 11:09 Simiens Crew??? wtf
Simiens Crew, por um mundo melhor

ok so please tell me that if they polite enough to leave a call sign, then they are at least willing to inform the devs of how they did it? :S

Top

m0nty
XOOPS is my life!
Joined:
2003/10/24 19:30
From Derbyshire/UK
Posts: 3335
(Show More) (Show Less)
#2 Posted on: 2005/1/28 11:13 Re: Siemens Crew??? wtf
I SAW THAT TOO!!!

portuguese script kiddies....

for a better world????

Quick somebody call GIJOE,

PROTECTOR Needs to know!

Top

tripmon
Module Developer
Joined:
2004/2/28 15:04
From /A\ ~[]~ [l_
Posts: 459
(Show More) (Show Less)
#3 Posted on: 2005/1/28 11:14 Re: Siemens Crew??? wtf
they did leave a call sign, we are still determining the point of entry. I will follow up once I know more.

Top


Site Hosting - PlanetXoops
ackbarr

Joined:
2002/10/2 14:40
From Missouri
Posts: 1735
(Show More) (Show Less)
#4 Posted on: 2005/1/28 11:21 Re: Siemens Crew??? wtf
Its a permissions thing on the server, Ima guessing..... Not sure how though.

Top


Tim
www.tswn.com | www.bf2online.com | aquaria.tswn.com | www.bf2142online.org
talunceford
Just can't stay away
Joined:
2002/8/14 11:29
From Oklahoma
Posts: 781
(Show More) (Show Less)
#5 Posted on: 2005/1/28 11:28 Re: Siemens Crew??? wtf
protector is installed on xoops.org. It looks like they gained access through an unpatched vulnerability in awstats. Awstats has been removed from the server, but so far it looks like the point of the attack was only graffiti.

Top


Site Hosting - PlanetXoops
ackbarr

Joined:
2002/10/2 14:40
From Missouri
Posts: 1735
(Show More) (Show Less)
#6 Posted on: 2005/1/28 11:35 Re: Siemens Crew??? wtf
Well, at least the hole has been found.

Top


Tim
www.tswn.com | www.bf2online.com | aquaria.tswn.com | www.bf2142online.org
talunceford
Just can't stay away
Joined:
2002/8/14 11:29
From Oklahoma
Posts: 781
(Show More) (Show Less)
#7 Posted on: 2005/1/28 11:54 Re: Simiens Crew??? wtf
yep that's good to hear :)

at least that's all it was is graffiti, and it identifies 1 more vulnerability that wasn't discovered till now :) s'pose that's 1 good thing about em..

Top

m0nty
XOOPS is my life!
Joined:
2003/10/24 19:30
From Derbyshire/UK
Posts: 3335
(Show More) (Show Less)
#8 Posted on: 2005/1/28 12:46 Re: Simiens Crew??? wtf
Quote:
s'pose that's 1 good thing about em..


It is never a good thing, only slightly less nasty than a full defacement. If someone spray painted my garage I'd be very upset.

Anyway, I missed the excitement but can assume that it was the same bandits that make it around to a lot of sites they scoop off this very board. I've seen attempts like this on mine in the past.

stats, if that is where the hole was then it should give pause to anyone using it (it's 3rd party, not core). I know stats are popular on a lot of sites but I've never been comfortable with them. Much safer and more efficient to keep that a function outside of xoops all together (same for database admin). Pulling aggregate info into a block is ok if done right but live stats and blingy numbers aren't worth the risk IMHO.

Oh, they are reading this thread right now... yuck.. have a good laugh jokers.

Top


no max no bling. goes double for mik. triple for the insane aliases of said lunatics
===========================
Not around here anymore. Way too many idiots, so sad.
DonXoop

Joined:
2003/11/26 22:46
From Third stone, bluish, under siege
Posts: 1178
(Show More) (Show Less)
#9 Posted on: 2005/1/28 14:04 Re: Simiens Crew??? wtf
FYI - awstats is a seperate application, not a xoops module. The vulnerability they exploited was "announced" on 1-17, but for some reason was not posted to the bugtrack mailing list.

Top


Site Hosting - PlanetXoops
ackbarr

Joined:
2002/10/2 14:40
From Missouri
Posts: 1735
(Show More) (Show Less)
#10 Posted on: 2005/1/29 14:21 Re: Simiens Crew??? wtf
Has awstats been confirmed as the entry point for these Simiens Crew attacks? One of my xoops sites just got attacked by these guys. As I don't admin the server I cannot easily check the logs etc. The machine also has telnet and ftp ports open so I wonder if they came in via another route...

The site was xoops 2.7.3.

Top

gravies
Not too shy to talk
Joined:
2004/8/18 14:25
Posts: 119
(Show More) (Show Less)

 Top   Previous Topic   Next Topic

1 2 »

You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.

[Advanced Search]