• twitter image
  • facebook image
  • youtube image
  • linkedin image
Language: CMS Made Simple Czech CMS Made Simple France CMS Made Simple Spain CMS Made Simple Hungary CMS Made Simple Russia CMS Made Simple Netherlands

All times are UTC




Post new topic Reply to topic  [ 19 posts ]  Go to page Previous  1, 2
Author Message
 Post subject: Re: Recent hacks and vulnerabilities
PostPosted: Sun Jun 29, 2008 12:49 pm 
Offline
Forum Members
Forum Members

Joined: Fri Jan 04, 2008 8:04 pm
Posts: 11
Hello,

Just for clarification on the previous point, do we delete the java postlet or is it ok sat in there please? It looks like the associated php files have been "nuked" to delete their content during the "diff" overwrite - does this effectively render the java postlet safe?

Thanks
Dave


Top
 Profile  
 
 Post subject: Re: Recent hacks and vulnerabilities
PostPosted: Mon Jun 30, 2008 12:09 pm 
If you want a more secure install I suggest - delete it.


Top
  
 
 Post subject: Re: Recent hacks and vulnerabilities
PostPosted: Mon Jun 30, 2008 3:31 pm 
Offline
Forum Members
Forum Members

Joined: Sat Apr 28, 2007 4:25 am
Posts: 66
To make it more simple for CMSMS users, I would suggest scheduling daily, weekly, and/or monthly back-ups with your web hosts - depending on how frequently you update your site's content.

I automatically back-up all of my sites daily to a shared hosting account, for example. This way, if a hacker does get in, you can simple restore it back to the last back-up file you have, and then change the database name, username, and password then update the config file and not have to go through all of the trouble that calguy listed.

Though...if you aren't making back-ups etc, you will have to follow calguy's steps.

_________________
EGS provides MMORPG services for WoW, FFXI, FFXIV, AION, Warhammer Online, Age of Conan, RuneScape, Guild Wars, Maple Story, Cabal Online, as well as most other free-to-play MMORPGs.

Our site is *proudly* powered by CMS Made Simple. :D

CMS Made Simple isn't just simply, it's ridiculously powerful, and suitable for virtually any site and niche. It easily allows us to maintain our site in which receives about 5,000 unique visitors per day.


Top
 Profile  
 
 Post subject: Re: Recent hacks and vulnerabilities
PostPosted: Tue Jul 01, 2008 11:26 pm 
Offline
Support Guru
Support Guru

Joined: Mon Jul 24, 2006 3:27 pm
Posts: 3690
Location: Paris
xmas3 wrote:
Last week a few of my sites based on CMS MS 1.2.x were hacked.
...I can send you the script if needed.


The crackers' script isn't interesting : what is very interesting is the http logS of its attack. Knowing the attack makes it possible to strengthem hardening the filtering rules in the "small security guide".

Pierre M.

_________________
-- Pierre, support team member. comodérateur du forum francophone.
Please read "how to submit installation/support requests" before posting. Don't send private messages to ask for support.
Want to contribute to CMSms ? Improve the wiki with your forum account.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 19 posts ]  Go to page Previous  1, 2

All times are UTC


Who is online

Users browsing this forum: No registered users


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Arvixe - A CMSMS Partner