FORUM IS CLOSED. PLEASE USE QUESTIONS / ANSWERS PAGE INSTEAD
Login  |  Forum  |  Search   

Board index » Development » Other




Post new topic Reply to topic  [ 4 posts ] 
 
Author Message
 Post subject: russian Hack [need traslate from polish to english]
 Post Posted: Thu Feb 02, 2012 11:46 am 
Offline

Joined: Sat Dec 25, 2010 5:58 pm
Posts: 7
My english is not so good, so i need translate my post from polish.

Ostatnio na dwóch stronach opartych o impresspages CMS, doszło do ataku przez formularze kontaktowe ruskich spamerów SEO - hackerów. przez formularz ładowany jest jakoś plik który ostatecznie wywala menadżera plików na serwer z dostępem do całego serwera. W obrębie zaindeksowanych w google stron pojawiają się tysiące podstron z ruskim spamem i linkami do jakichś pierdół. Jest to dość uciążliwe, bo strona natychmiast traci swoje pozycje, przez nasycenie rosyjskimi słowami kluczowymi. Warto się temu przyjrzeć z bliższa nieco dokładniej. Ja już niby problem zażegnałem u siebie, ale to sie może powtarzać.

_________________
serwis informacyjny Art Sites
Haft Komputerowy


Top 
 Profile  
 
 Post subject: Re: russian Hack [need traslate from polish to english]
 Post Posted: Fri Feb 03, 2012 12:32 am 
Offline
Project Developer

Joined: Tue Apr 28, 2009 9:43 am
Posts: 1720
I'm not sure about the quality of google translate, but as I understand, your website have been hacked? Can you please provide ImpressPages version number that has been used? Do you know some additional technical information how it was done?


Top 
 Profile  
 
 Post subject: Re: russian Hack [need traslate from polish to english]
 Post Posted: Fri Feb 03, 2012 6:38 am 
Offline

Joined: Sat Dec 25, 2010 5:58 pm
Posts: 7
It is ImpressPages CMS 1.0.8

i try to explain.
I think, and server logs says that - attack was from contact form. they snet me one file, in php with (preg_match and 50000 some signs). When I point browser to that file i have file manager with all permission to the server and option of bruteforce database :)

I think it was a russian SEO, because, they put to my site 1k files in php, which only displays im my domain anchors to russian www.

they hacked only some folder. At one ww it was /video/ and in other, it was /file/

try to see in gogle: site:www.grawertop.pl

and look at the russian site (cache)


I hope you understand me...

_________________
serwis informacyjny Art Sites
Haft Komputerowy


Top 
 Profile  
 
 Post subject: Re: russian Hack [need traslate from polish to english]
 Post Posted: Sun Feb 05, 2012 2:42 pm 
Offline
Project Developer

Joined: Tue Apr 28, 2009 9:43 am
Posts: 1720
For others to know. ImpressPages prior 1.0.13 has security hole. If you are using earlier version, please update.


Top 
 Profile  
 
Display posts from previous:  Sort by  
 
Post new topic Reply to topic  [ 4 posts ] 

Board index » Development » Other


 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron