Get XOOPS XOOPSXOOPS FAQFAQ ForumsForums NewsNews ThemesThemes ModulesModules
New Posts New Topics All Posts All Forums Index General Modules Themes Development International XOOPS.org

Search

Donat-O-Meter

Make donations with PayPal!
Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $65.00
Net Balance: $61.80
Left to go: $38.20

Donations
studioC  ($25)May-17
Anonymous ($15)May-16
Anonymous ($25)May-4

Learn XOOPS Core

Local Support

Advertisement

XOOPS Code hosted on SourceForge

Cumulus Tag Cloud

2 2.5 2.6 3.0 87 2013 Abuse Amazon AntiHarvesting AntiMalUser AntiSpam API banner Beats billige black Blocks blue Bootstrap Captcha cell Christmas chronolabs content Conversion demo docek download Dresses editor evden eve facebook floor free herre Honeypot Human IP IPInfoDB jQuery kantor lamps Language log logger Lucire mobile module modules Monster MyAlbum-p newbb news Notices online PageRank Password Permissions pink Plugin portal preloader Prevention profile project propose Protector publisher Rights rmcommon Room sale security Server site SmartClone Smarty SOAP Songlist Spam stem Studio tag tags tdmcreate template Theme themes TinyMCE userlog website Whitepaper XIPS XML XooLaT xoops Xortify Yolande ZendFramework

New Users

Registering user

# 136021

dressshop

Welcome to XOOPS!




Bottom   Previous Topic   Next Topic  Register To Post

(1) 2 »


#1 Posted on: 2012/3/23 15:07 Username & Password HACK
I have been using xoops for several years on hobby sites, last year I started using xoops as a backend for my business website www.eurodirectrentals.com, as a security thing I added a little code to a page so when my clients edit their details I get an automated email, today I got several in a short space of time which is unusual...
On checking the details I noticed that the clients original emails had been replaced with a 'free' gmx.com email address....
The clients original password has not changed (I have a backup of passwords for reference).

As yet I am stumpped as to how this has happened, any light would be good as I have had to close the backend until I get to the bottom of this issue.
Currently using 2.4.4

Thanks in advance

Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)


#2 Posted on: 2012/3/23 21:13 Re: Username & Password HACK
Have you contacted any of those customers and ask if they have had anything strange happen?

What modules do you have installed?

It is possible you have an unsecure module on your system that somehow allowed a hacker access to your database. This is not necessarily a xoops issue but we can start there.

And what have you modified in your system?

You may want to upgrade to 2.4.5 and make sure you have the protector module installed if you don't already.



Top


Attending College working towards Bachelors in Software Engineering and Network Security.
redheadedrod
Home away from home
Home away from home
Joined:
2008/2/26 10:05
From Grand Rapids, MI
Group:
Registered Users
Posts: 1067
(Show More) (Show Less)


#3 Posted on: 2012/3/24 4:38 Re: Username & Password HACK
Hi redheadedrod, thx for the quick reply, firstly I don't think it is a xoops issue, I have several hobby sites for flight sim enthusiasts & other sites constructed for friends all of which use xoops as the core, none of these have ever been 'attacked'.

I have checked some of the passwords used by my clients in an md5 hack tool which unfortunately reveals their passwords correctly, that said the 'attacker' must also have the clients username to be able to log in, this is where I am stumpped.

There are several code snippets that use the core data, I am currently working through these to see if there is any information 'leaks'.

Modules used...
System 2
User Profile 1.57
Smart FAQ 1.08
News 1.64
XForum 5.46
Protector 3.4

Today I will upgrade to the latest version of xoops.

UPDATE:
Installed upto 2.5.4, unfortunately got a white screen after updating everthing, reverting back to 2.4.4 and updating to 2.4.5

Thanks for your interest.

Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)


#4 Posted on: 2012/3/24 8:28 Re: Username & Password HACK
A hack could be the case but don't opt out social engineering. Are you sure webmaster logins and passwords are still private? Same question for provider adminpanel...

Top


The Dutch speaking XOOPS community has moved!
____________________________________

For Dutch support now go to www.nlxoops.nl
flipse
Moderator
Moderator
Joined:
2005/9/15 4:11
From The Netherlands
Group:
Registered Users
Community Coordinator (temporary)
Posts: 699
(Show More) (Show Less)


#5 Posted on: 2012/3/24 9:25 Re: Username & Password HACK
UPDATE 2:
2.4.5 now installed and working, Protector 3.51 on, since installing there have been 2 attempts to get into the site, a me testing Protector is working and b not me but someone trying to login as a user.

a. ISOCOM
b. BRUTE FORCE

It looks like Protector has done the job of stopping the entry.

I will take into consideration the posibility of social engineering, but after the Protector report I am convinced there has been a hacker of some sort at work.
As for if the Usernames & passwords are in fact private.. how would I know if they were not?
Admins count for 3 of the members, myself included, the other two are family so I doubt they would be involved.

Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)


#6 Posted on: 2012/3/24 11:10 Re: Username & Password HACK
It would be a good idea for anyone having admin access to change their passwords as well as the users accounts that were effected.

Another thing to look into is xortify which is supposed to block such hackers altogether.

But you are moving in the right direction at a minimum.

In one of my security classes they mentioned that a very large percent of break ins can be due to social engineering where they guess a password...



Top


Attending College working towards Bachelors in Software Engineering and Network Security.
redheadedrod
Home away from home
Home away from home
Joined:
2008/2/26 10:05
From Grand Rapids, MI
Group:
Registered Users
Posts: 1067
(Show More) (Show Less)


#7 Posted on: 2012/3/24 12:32 Re: Username & Password HACK
After all this I have just had 2 members details changed, nothing in Protector so I have to assume the database has in fact been breached....



Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)


#8 Posted on: 2012/3/25 6:31 Re: Username & Password HACK
UPDATE 3:
After checking the 'hacked' accounts I think redheadedrod & flipse are probably right, possibly a social engineering problem, on the client accounts that have been affected I ran their passwords through an md5 decoder which revealed their actual password. I have to say that most of the passwords were very 'un-original' and in most cases were simply a name....

There has been no breach of the database, so the only way in is to have username and password.

So the question is now do I change all my clients passwords?

Is there a xoops module that can do this and email the clients the new password?

So far only 5 accounts have been affected, with 600+ clients this is looking like a huge task !!

Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)


#9 Posted on: 2012/3/25 7:41 Re: Username & Password HACK
Changing all passwords seems a bit drastic, I would only do this for the 5 affected accounts.

You could send all your clients a warning and ask them to change their passwords in case they are easy to guess. So you make them responsible themselves, it's in their own interest private data keeps save.

Top


The Dutch speaking XOOPS community has moved!
____________________________________

For Dutch support now go to www.nlxoops.nl
flipse
Moderator
Moderator
Joined:
2005/9/15 4:11
From The Netherlands
Group:
Registered Users
Community Coordinator (temporary)
Posts: 699
(Show More) (Show Less)


#10 Posted on: 2012/3/25 7:48 Re: Username & Password HACK
Drastic yes !!

I just want to be sure that this never happens again, I am currently going through all passwords and checking them in the hash tool to see if they are in fact secure.
I reality we only store names, phone numbers and addresses... nothing else so there is no benefit to anyone seeing these accounts.

Thank you for your help, it is very much appreciated.

Top

mutley8
Just popping in
Just popping in
Joined:
2012/3/23 14:41
From UK
Group:
Registered Users
Posts: 9
(Show More) (Show Less)




(1) 2 »



You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You cannot vote in polls.
You cannot attach files to posts.
You cannot post without approval.
You cannot use topic type.
You cannot use HTML syntax.
You cannot use signature.

[Advanced Search]