Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-03-26, 03:27 PM   #1
GunnCat
You can now put whatever you want in this space :)
 
Join Date: Aug 2004
Posts: 547
Send a message via ICQ to GunnCat
Arrow WARNING: AWStats Users!

If you are using AWSTats you should read this asap:
http://seclists.org/lists/incidents/2005/Mar/0019.html

We believe this is how we were exploited.
GunnCat is offline   Reply With Quote
Old 2005-03-26, 03:43 PM   #2
Verbal
Verbal prefers 56K
 
Verbal's Avatar
 
Join Date: Sep 2003
Location: Chicago, IL
Posts: 563
Send a message via ICQ to Verbal
Check this..

http://www.greenguysboard.com/board/...hlight=awstats

same issue?
__________________
Verbal
Verbal is offline   Reply With Quote
Old 2005-03-26, 03:43 PM   #3
RonaldBiggs
Are you sure you're an accredited and honored pornographer?
 
Join Date: Nov 2004
Posts: 60
http://www.greenguysboard.com/board/...hlight=awstats

R
__________________
RonaldBiggs is offline   Reply With Quote
Old 2005-03-26, 03:43 PM   #4
Verbal
Verbal prefers 56K
 
Verbal's Avatar
 
Join Date: Sep 2003
Location: Chicago, IL
Posts: 563
Send a message via ICQ to Verbal
lol... that is spooky.
__________________
Verbal
Verbal is offline   Reply With Quote
Old 2005-03-26, 04:02 PM   #5
GunnCat
You can now put whatever you want in this space :)
 
Join Date: Aug 2004
Posts: 547
Send a message via ICQ to GunnCat
Yah same one bro. Too bad we didn't see that article before. 4th day down the drain. Looks like we might be up by tonite though. Then I can see all the customer cancellation emails from CCBill. Yay.
GunnCat is offline   Reply With Quote
Old 2005-03-26, 05:42 PM   #6
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
my host did the update so i blame them with all what is going wrong with aw stats , they wanted to take that in their own hands because i was fucking up their server, so easy pick
stuveltje is offline   Reply With Quote
Old 2005-03-26, 08:15 PM   #7
chaser
Internet! Is that thing still around?
 
Join Date: Sep 2004
Posts: 3
Thanks for the heads up. My server was hacked the last couple days, I assume this is how they hacked it. I'll double check to make sure they installed the new version.
chaser is offline   Reply With Quote
Old 2005-03-26, 08:17 PM   #8
DangerDave
Bonged
 
DangerDave's Avatar
 
Join Date: Mar 2003
Location: BrisVegas, AUSTRALIA
Posts: 4,882
There is also a recent security hole in phpBB.. 2nd one in month or so

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=267563

DD
__________________
Old Dollars >>>> Now with over 90 Hosted Free Sites <<<<
DangerDave.com.au - Adult Links to Free Porn
DangerDave is offline   Reply With Quote
Old 2005-03-26, 10:11 PM   #9
Useless
Certified Nice Person
 
Useless's Avatar
 
Join Date: Oct 2003
Location: Dirty Undies, NY
Posts: 11,268
Send a message via ICQ to Useless
I was doing some research on this and I found that as long as your awstat.pl is protected by htaccess you are fine. If you have it publicly viewable, well then you're in trouble. If you reach it like this: http://domain.com/cgi-bin/awstats/awstats.pl -that's bad. If it can only be accessed via CPanel, which is a protected area, you should be fine without the update.

Do people really install Awstats in public directories? Why?
__________________
Click here to purchase a bridge I'm selling.
Useless is offline   Reply With Quote
Old 2005-03-27, 01:52 AM   #10
GunnCat
You can now put whatever you want in this space :)
 
Join Date: Aug 2004
Posts: 547
Send a message via ICQ to GunnCat
We had ours in an unprotected dir, but the domain isn't one we use. Actually, we had disabled it for most of our sites since it's a resource hog anyways. We had two sites we host for people that had it up still. I always thought it was kind of strange it wasn't behind htaccess, but I forgot to tell my partner.
GunnCat is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 07:17 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc