Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 06-13-2005, 06:31 PM
Vantage's Avatar
Vantage Vantage is offline
Registered User
Junior Member
 
Location: Orlando Fl
Send a message via ICQ to Vantage Send a message via AIM to Vantage
6/13/05 AWstats security hole.

Hello everyone.

We are currently running AWstats 6.4. This is the latest version.

We have just discovered that there is a security hole in this version. A few sites have been defaced based on this and I am sure others will be as well.

This is just a warning. We are looking at the code ourseves and hoping to find the flaw. Untill then, There is no update available.
Reply With Quote
  #2  
Old 06-13-2005, 07:52 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Could the box have been compromised by the earlier <= 6.4 version exploit before you upgraded? I've heard of a few boxes being hit recently that the owners suspect had been compromised several months ago.
Reply With Quote
  #3  
Old 06-14-2005, 12:06 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Not sure but we will are going to do everything we can to be 100% sure AW is fully fixed and the box is 100% safe..

This is part of what I told the techs after the mod_rewrite rule anything they might have to fix server wide must be posted, even if it does not have to be done in the end I would rather be safe then sorry..
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #4  
Old 06-14-2005, 12:31 AM
Vantage's Avatar
Vantage Vantage is offline
Registered User
Junior Member
 
Location: Orlando Fl
Send a message via ICQ to Vantage Send a message via AIM to Vantage
It doeant look like anything was compromised. Some defacements seams to be the worst of it.

We are working on AWstats. It would be nice if they released a patched version.

Last edited by Vantage : 06-14-2005 at 12:57 AM.
Reply With Quote
  #5  
Old 06-14-2005, 05:17 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
Are you able to contact the people who's site are hit, or is it more of a wait for the client to realise their sites been hit, then contact us.
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #6  
Old 06-14-2005, 07:06 PM
Dean's Avatar
Dean Dean is offline
Registered User
Admin
 
All resellers that have defaced sites that we are aware of have been contacted.

We are updating all sites on the Unix servers that are running old versions of AWStats. All domains will be running v6.4.
Reply With Quote
  #7  
Old 06-15-2005, 08:36 AM
cambodia's Avatar
cambodia cambodia is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Phnom Penh . Cambodia
Send a message via ICQ to cambodia Send a message via AIM to cambodia Send a message via Yahoo to cambodia Send a message via Skype to cambodia
so if we disable it we will safe from bug hole ? until everything complete then we enable it , can this way is good way ?
__________________
I Love Cambodia
Reply With Quote
  #8  
Old 06-15-2005, 09:16 AM
Dean's Avatar
Dean Dean is offline
Registered User
Admin
 
AWStats has been updated to latest for all users.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Anti-virus software hole can knock out your system admin Chit Chat Public 0 01-15-2004 05:30 PM
Major security hole in phpmyAdmin somereseller Chit Chat Public 5 06-19-2003 10:12 AM


All times are GMT -5. The time now is 06:35 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.71524 seconds with 19 queries
[Output: 71.65 Kb. compressed to 66.42 Kb. by saving 5.23 Kb. (7.30%)]