Author Topic: How secure and exploitable is phpmotion?  (Read 4262 times)

asentertainment

  • Newbie
  • *
  • Posts: 46
How secure and exploitable is phpmotion?
« on: July 13, 2007, 12:59:38 PM »
Greeting,

I'm curious how secure and exploitable phpmotion is.. relating more to the fact of IF i decide to use phpmotion, how easy would it be for someone to deface my website or exploit my server?

This is a great concern of mine and i'm sure its on the mind of other users.

Thank you in advance for your response.

asentertainment

  • Newbie
  • *
  • Posts: 46
Re: How secure and exploitable is phpmotion?
« Reply #1 on: October 23, 2007, 07:15:33 PM »
just curious if anyone has encountered any issues concerning security.

Ezra

  • Newbie
  • *
  • Posts: 6
Re: How secure and exploitable is phpmotion?
« Reply #2 on: June 17, 2009, 12:59:08 PM »
So! I know this thread is about 2 years old... but my website just got hacked tonight!!! It was defaced by a hacker by the name of lo$er.0. You can even see a bunch of websites he has hacked into on www.arabic-m.com - fantastic!

Well, after a while of searching and stressing and frustration, I finally found the files that had been altered by our good friend lo$er.0 --> sessions.php and config.php in the classes folder. I am not sure what are some security measures I can take to prevent this from ever happening again. How do they have access to my web server? It IS possible I had the classes folder set to 777 file permissions, as that is what they were when I started looking out for possible causes of the defacement. But its also possible the hackers changed those file permissions. Is that possible?

Anyway, I just thought I'd let people know that SITES DO GET HACKED (mine isn't even finished yet and people don't go on it) so lock your doors, bar your windows, and backup your websites!!!

frankie

  • Administrator
  • Hero Member
  • *****
  • Posts: 5947
  • PHPmotion Developer
Re: How secure and exploitable is phpmotion?
« Reply #3 on: June 17, 2009, 01:08:34 PM »
it might help if you posted your site url?

Ezra

  • Newbie
  • *
  • Posts: 6
Re: How secure and exploitable is phpmotion?
« Reply #4 on: June 17, 2009, 01:12:27 PM »
Well, I have fixed the problem by replacing those two files with the original ones (thankfully they weren't redesigned files that I have edited) so it's not necessary for me to put my site URL up. But, I am with Cirtex Hosting sharing a server if that helps.

EDIT * Basically, I'm just trying to let people know that hackers DO hack, and I don't want other people to find they're files have been overwritten without a backup. Also, I am looking to see if anyone knows of any ways to prevent such attacks for the future.
« Last Edit: June 17, 2009, 01:21:40 PM by thesilmister »

frankie

  • Administrator
  • Hero Member
  • *****
  • Posts: 5947
  • PHPmotion Developer
Re: How secure and exploitable is phpmotion?
« Reply #5 on: June 17, 2009, 01:14:58 PM »
yeah well thats your answer, cirtex servers have been hacked a few times in the past.

i guess there are still issues, but it has nothing to do with phpmotion.

what version of phpmotion was this?
« Last Edit: June 17, 2009, 01:18:17 PM by frankie »

Ezra

  • Newbie
  • *
  • Posts: 6
Re: How secure and exploitable is phpmotion?
« Reply #6 on: June 17, 2009, 01:25:32 PM »
It's on phpmotion v3. I guess I should be posting this in another forum and not phpMotion v1... sorry. I was just searching for security/exploitability in phpmotion and I was just replying to this thread.

Thanks for that, frankie. I will contact Cirtex hosting and see what they have to say. I didn't think it was phpmotion's fault, but not knowing that Cirtex have such issues its probably a great place to post such issues seeing as many people on this site would use Cirtex as a host.

Cheers.

frankie

  • Administrator
  • Hero Member
  • *****
  • Posts: 5947
  • PHPmotion Developer
Re: How secure and exploitable is phpmotion?
« Reply #7 on: June 17, 2009, 01:42:09 PM »
from that list it seems that NS75 and NS76 are affected, a bunch of sites got hit.

is your site the one with the forum?
« Last Edit: June 17, 2009, 01:45:36 PM by frankie »

Ezra

  • Newbie
  • *
  • Posts: 6
Re: How secure and exploitable is phpmotion?
« Reply #8 on: June 17, 2009, 11:29:23 PM »
Yeah, mine has the forum. I contacted Cirtex and they said they are able to replace the public_html folder from backups that they run. YES! They run backups! I already have most of the files on my computer, but it saves me a lot of hassle, thankfully.

Anyways, thanks for the help :-)

camarados

  • Newbie
  • *
  • Posts: 14
Re: How secure and exploitable is phpmotion?
« Reply #9 on: June 18, 2009, 03:34:00 AM »
Also my website was hacked last night.
See also my topic here: http://phpmotion.com/forum/index.php/topic,12717.msg75860.html

Its looke they changed the index.php file.
After replacing this file with the original index.php file the website was up and running again.
But, after 5 minutes it was hacked again. So maybe there s a script that is somewere running?  ???

Maybe more people has their site hacked these days?

What can i do?
replace config files?
change passwords?
secure upload script?

Please advise





den48248

  • Guest
Re: How secure and exploitable is phpmotion?
« Reply #10 on: June 18, 2009, 04:14:03 AM »
Are you on cirtex?

camarados

  • Newbie
  • *
  • Posts: 14
Re: How secure and exploitable is phpmotion?
« Reply #11 on: June 18, 2009, 04:20:58 AM »
No, another (dutch) host.

matchmanhattan

  • Newbie
  • *
  • Posts: 7
Re: How secure and exploitable is phpmotion?
« Reply #12 on: August 14, 2009, 09:15:01 PM »
Hi Frankie,


You are correct.  My site was with cirtex on NS75 and ns76.  I got hacked too!! 
After some other unhappiness with Cirtex, I moved to another host and it has been very good. Thank God.

from that list it seems that NS75 and NS76 are affected, a bunch of sites got hit.

is your site the one with the forum?