Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2012-05-04, 04:18 PM   #1
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
OpenX Security Notice

http://blog.openx.org/05/security-up...penx-28-users/

Quote:
OpenX takes security seriously. If ever we find an issue, we address it quickly and communicate any updates as soon as possible. A recent security issue with OpenX versions 2.8.0 - 2.8.8 means users of these versions of the platform should take the following steps:

1. Secure their servers by removing the files being exploited:

www/admin/account-settings-debug.php
www/admin/plugin-index.php
www/admin/plugin-settings.php
www/admin/admin-user.php
2. Removing these scripts will impact some of the user/plugin management systems, but will not affect existing users/plugins, and will not affect ad serving.

3. Replace the www/admin/dashboard.php file with the one in this archive so as to not break the login process.

Users can tell if they have been affected by this by checking for a rogue admin user named “openx-manager” in their UI at http://<your_admin_domain>/www/admin/admin-access.php

If the above user is found, it should be removed, and a full security audit should be performed.

We strongly encourage users to lock down their config file. Additionally, users should notify security@openx.com if they ever become aware of a security matter.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2012-05-04, 05:16 PM   #2
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
I followed all the above steps.

I haven't been hacked.

This step lost me though
"3. Replace the www/admin/dashboard.php file with the one in this archive so as to not break the login process."
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2012-05-04, 08:15 PM   #3
Allfetish
If you really need money, you can sell your kidney or even your car
 
Join Date: Mar 2005
Posts: 373
Bastards got me but I had /admin/ locked down so maybe they had troubles doing much I don't know. I see the rougue user added 4-14 but no evidence of any malware being served yet. Having to do a full audit now.

Quote:
Originally Posted by Cleo View Post
I followed all the above steps.

I haven't been hacked.

This step lost me though
"3. Replace the www/admin/dashboard.php file with the one in this archive so as to not break the login process."
I think it means rename/remove the existing dashboard.php file and then download the dashboard.zip file they link to, unzip it, and put that in the place of the old dashboard.php file. You have to go to the original announcement to get that file.

Edit: Here are some more technical details about the hack I found interesting
http://www.infosecstuff.com/openx-cs...ely-exploited/

Last edited by Allfetish; 2012-05-04 at 08:43 PM..
Allfetish is offline   Reply With Quote
Old 2012-05-04, 11:01 PM   #4
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
Quote:
Originally Posted by Allfetish View Post
I think it means rename/remove the existing dashboard.php file and then download the dashboard.zip file they link to, unzip it, and put that in the place of the old dashboard.php file. You have to go to the original announcement to get that file.
Got it, this file.
http://www.openx.com/downloads/dashboard.zip

My OpenX was hacked a few years ago. It was a real mess to straighten out. Don't want to ever go through that again.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2012-05-05, 11:37 AM   #5
LeRoy
"Young dumb and full of cum"
 
LeRoy's Avatar
 
Join Date: Jun 2007
Location: Porn Valley
Posts: 2,370
Send a message via ICQ to LeRoy Send a message via AIM to LeRoy Send a message via Yahoo to LeRoy
Ouch!

Glad I deleted OpenX a couple months ago
LeRoy is offline   Reply With Quote
Old 2012-05-06, 06:24 PM   #6
bDok
bang bang
 
bDok's Avatar
 
Join Date: Mar 2005
Location: SD/OC/LA
Posts: 3,241
Send a message via ICQ to bDok
Should I still take these steps if I'm on 2.8.8? Or is that safe?
__________________
submit to Nymphotic
submit to Moistlace
bDok is offline   Reply With Quote
Old 2012-05-07, 10:45 AM   #7
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
Quote:
Originally Posted by bDok View Post
Should I still take these steps if I'm on 2.8.8? Or is that safe?
2.8.8 is also affected. There is no fix yet.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2012-05-08, 12:35 AM   #8
bDok
bang bang
 
bDok's Avatar
 
Join Date: Mar 2005
Location: SD/OC/LA
Posts: 3,241
Send a message via ICQ to bDok
Quote:
Originally Posted by cd34 View Post
2.8.8 is also affected. There is no fix yet.
bah. Applying changes for this then now. Thanx.
__________________
submit to Nymphotic
submit to Moistlace
bDok is offline   Reply With Quote
Old 2012-05-12, 03:49 PM   #9
bDok
bang bang
 
bDok's Avatar
 
Join Date: Mar 2005
Location: SD/OC/LA
Posts: 3,241
Send a message via ICQ to bDok
2.8.9 is out. update away!
__________________
submit to Nymphotic
submit to Moistlace
bDok is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:43 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc