Security Breach in CMSMS website?

General project discussion. NOT for help questions.
Post Reply
rodel
New Member
New Member
Posts: 5
Joined: Thu Mar 22, 2012 10:11 am

Security Breach in CMSMS website?

Post by rodel »

Hi all,

While googling for a new CMSMS theme I found this
_themes.cmsmadesimple.org/uploads/ctrlH/notes/9485.html
or
_themes.cmsmadesimple.org/uploads/ctrlH/

It looks like a spammer modified a theme and added an affiliate link to a spyware website?

I think admins should remove the above.
rodel
New Member
New Member
Posts: 5
Joined: Thu Mar 22, 2012 10:11 am

Re: Security Breach in CMSMS website?

Post by rodel »

Look like no one cares about this problem?? Eh :(

In google search enter:

spy inurl:themes.cmsmadesimple.org


There are hundreds of pages with the same affiliate link and because the CMSMS website is old and respected in google's eyes the spam pages with affiliate links are rank very high in google search for many competitive keywords...

The CMSMS website may be banned by google for spam one day..

Fight SPAM! >:D CMSMS developers looks at this problem.
User avatar
paulbaker
Dev Team Member
Dev Team Member
Posts: 1465
Joined: Sat Apr 18, 2009 10:09 pm
Contact:

Re: Security Breach in CMSMS website?

Post by paulbaker »

rodel wrote:In google search enter:

spy inurl:themes.cmsmadesimple.org
Hmmm, I see what you mean. See screenshot. That's not good. I hope someone can fix it. :-[
Attachments
Google results page
Google results page
User avatar
Rolf
Power Poster
Power Poster
Posts: 7825
Joined: Wed Apr 23, 2008 7:53 am
Contact:

Re: Security Breach in CMSMS website?

Post by Rolf »

We have found the folder and removed it several times. We didnt ignore the appreciated warnings from you.
Problem is the folder is coming back to the server, so the real issue is still there... As you probably know our old webserver is hacked and we are transfering all sites to the new one. The Themes website however is still on the old one... But at the moment we dont have the man power to do this last transfer. Knowing Ted lives in the 'Sandy' area and DrCss is in the middle of moving himself. I try to delete the folder again when I have a moment.
Thanks for your warnings and (hopefully) patience!

Rolf
- + - + - + - + - + - + -
LATEST TUTORIAL AT CMS CAN BE SIMPLE:
Migrating Company Directory module to LISE
- + - + - + - + - + - + -
Image
User avatar
Dr.CSS
Moderator
Moderator
Posts: 12711
Joined: Thu Mar 09, 2006 5:32 am

Re: Security Breach in CMSMS website?

Post by Dr.CSS »

Search using that bit of text no longer produces those results, so it is fixed...
Post Reply

Return to “General Discussion”