![]() |
|
|||||||
| Network / Server Status Please check often for network / Server updates here! |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
6/13/05 AWstats security hole.
Hello everyone.
We are currently running AWstats 6.4. This is the latest version. We have just discovered that there is a security hole in this version. A few sites have been defaced based on this and I am sure others will be as well. This is just a warning. We are looking at the code ourseves and hoping to find the flaw. Untill then, There is no update available. |
|
#2
|
|||||||||||
|
|||||||||||
|
Could the box have been compromised by the earlier <= 6.4 version exploit before you upgraded? I've heard of a few boxes being hit recently that the owners suspect had been compromised several months ago.
|
|
#3
|
||||
|
||||
|
Not sure but we will are going to do everything we can to be 100% sure AW is fully fixed and the box is 100% safe..
This is part of what I told the techs after the mod_rewrite rule anything they might have to fix server wide must be posted, even if it does not have to be done in the end I would rather be safe then sorry.. ![]()
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#4
|
||||
|
||||
|
It doeant look like anything was compromised. Some defacements seams to be the worst of it.
We are working on AWstats. It would be nice if they released a patched version. Last edited by Vantage : 06-14-2005 at 12:57 AM. |
|
#5
|
||||
|
||||
|
Are you able to contact the people who's site are hit, or is it more of a wait for the client to realise their sites been hit, then contact us.
|
|
#6
|
||||||||||||
|
||||||||||||
|
All resellers that have defaced sites that we are aware of have been contacted.
We are updating all sites on the Unix servers that are running old versions of AWStats. All domains will be running v6.4. |
|
#7
|
||||
|
||||
|
so if we disable it we will safe from bug hole ? until everything complete then we enable it , can this way is good way ?
__________________
I Love Cambodia ![]() |
|
#8
|
||||||||||||
|
||||||||||||
|
AWStats has been updated to latest for all users.
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Anti-virus software hole can knock out your system | admin | Chit Chat Public | 0 | 01-15-2004 05:30 PM |
| Major security hole in phpmyAdmin | somereseller | Chit Chat Public | 5 | 06-19-2003 10:12 AM |