View Full Version : Hacked Using 3.4
GusLinares
04-05-2007, 02:27 PM
After our "political problems", getting sued, we just recd another blow, our site just got hacked this morning.
Was able to add a new user, add articles, changed index.php, and displayed a screen saying "your site just hacked".
Luckily I copied my whole site last night to a local linux machine so I could test the 3.5 upgrade. So I managed to replace index.php and site is working again.
But I am not really sure how I was hacked so perhaps it will happen again.
I have contacted vivvo support as I am not sure how hacker was able to do this, or if other files have also been changed or added, not sure if to make upgrade now.
So keep an eye on your sites in case you also get attacked.
Regards
Gus
Vivvo CMS v3.5 introduced security fixes for problems found in v3.4, and the exploits for this version are already well-known. We strongly advise everyone to install latest upgrade.
MuhaciR
04-06-2007, 10:28 AM
I think you are sure that you have updated all security issues. Yes you are right.
________
EASY VAPE (http://vaporizer.org/reviews/easy-vape)
________
White Girls Cam (http://www.girlcamfriend.com/webcam/white-girls/)
Frankc
04-11-2007, 10:05 AM
Somebody seems to be able to hack into a cPanel server with relative strong security (managed by platinumservermanagement.com).
Seems like Islamic hacker that overwrited all the config.php files for several websies.
I heard the advice to upgrade to latest version yes but it is unfair to force the new layout changes upon clients too.
I am sorry but simply HATE the new layout but am now between two fires. On the one side layout changes for the new version that I hate and on the other side security issues with version 3.4.
boccio
04-11-2007, 10:32 AM
I am sorry but simply HATE the new layout but am now between two fires. On the one side layout changes for the new version that I hate and on the other side security issues with version 3.4.
Frank, nobody is forcing you to use anything. I really don't know how did you manage to come to the conclusion that you either have to use "hated" 3.5 or 3.4 with security issues?
We already informed you that 3.5 upgrade comes in two "flavors".
1. "Clean install" that will override complete 3.4 and give you the new layout
2. "Compatibility upgrade" that will keep 3.4 look and feel and install only security updates.
This is clearly stated in the announcement and Forum, and everybody received both upgrades. Still, you keep saying that we force you to use something you hate? I really don't understand...
Trable
04-11-2007, 11:46 AM
Verry funny that secnd time..
I think ferst time was teh db_cofig probleem that was solfd..by vivvo, but scend time.. was my debt.. becus he had ather file in de dir file i did not see it.. teh name was c.jpg.php that is shell file 2007 but i did make it cline now.. if he hack me agen than he is good hacker..
I dont know that was MUhacir or some one eals but that was turkish hacker agen..
Regards
Trable
chatfan
04-11-2007, 12:40 PM
This is true, I upgraded my site to 3.5 and kept my layout and settings. In fact the upgrade improved a couple of things. It gave me more tools to manage my theme and menu layout ideas.
I also think its a bit silly to turn your personal taste into a general statement, as if this is the feeling of everybody here. I prefer the new look over the previous one and would have liked to build on the new theme instead of the old one. In future sites I definitely will, its a step forward from my point of view.
To be honest I can't imagine why anyone would buy a flexible and advanced CMS like this one just to make it look like everybody else :eek:
Seriously, its dead easy to make your own theme
We already informed you that 3.5 upgrade comes in two "flavors".
1. "Clean install" that will override complete 3.4 and give you the new layout
2. "Compatibility upgrade" that will keep 3.4 look and feel and install only security updates.
This is clearly stated in the announcement and Forum, and everybody received both upgrades. Still, you keep saying that we force you to use something you hate? I really don't understand...
GusLinares
04-11-2007, 12:49 PM
I have to agree with Chatfan on this issue.
In my opinion new version provides greater control over CMS and templates.
I am currently using v3.5 with my existing template set.
But I will also be moving on to adapting the new templates to my site. I think new ones look quite cool also guys.
Gus
andy77
04-11-2007, 12:54 PM
To be honest I can't imagine why anyone would buy a flexible and advanced CMS like this one just to make it look like everybody else :eek:
Seriously, its dead easy to make your own theme
Exactly the point :)
Frankc
04-11-2007, 01:39 PM
I have to apologise because I was under the impression that the upgrade will also change the layout etc.
Will get the upgrade version as soon as my server is up again. (The whole server went down after I restarted it and still down for couple of hours)
I also liked a number of aspects of the default theme from 3.4, but I installed the clean install of 3.5 last night, restored my articles from the 3.4 backup, and after playing around with font sizes and so forth in the various css files for a few hours (I am an extreme novice at programming and css), I found it was fairly easy to recreate all of the design elements from 3.4 that I wanted.
I agree 3.5 is great and easily customizable.
Trable
04-13-2007, 12:12 PM
Hi,
i have find that i dont know if that the bug;
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0574
vBulletin® v3.8.4, Copyright ©2000-2012, Jelsoft Enterprises Ltd.