Welcome to Geeklog, Anonymous Friday, December 27 2024 @ 11:54 pm EST

Geeklog Forums

My GeekLog was hacked; any known security fixes?


Status: offline

ChrisN

Forum User
Newbie
Registered: 01/25/04
Posts: 3
grumpy
Hi all,

I am still running v1.4.0sr3. Yesterday my site was hacked by a phishing operation, who installed a fraudulent site under /backups in GeekLog. My ISP wants me to look for a security fix for GL. Is anyone aware of known vulnerabilities like this? Would upgrading to the new v1.4.1 help?

My GL has definitely been under attack. I was getting a lot of users who were posting spam to the blog, so I had to stop allowing legitimate users to post. Then they started posting spam in the comments, & since there was no way to approve comments individually, I disabled all comments (and trackbacks). Now I'm the only authorized poster on a somewhat de-functionalized site.

Any suggestions would be appreciated!

Thanks
--ChrisN
 Quote

Status: offline

Laugh

Site Admin
Admin
Registered: 09/27/05
Posts: 1470
Location:Canada
I am not sure if there are any known security vulnerabilities in your version of geeklog but it is always best to upgrade to the latest version. My geeklog site got defaced a while ago but the hackers actually got in through a security flaw in another web site that was running on the same server.

To stop SPAM, I would install 1.4.1, it has support for the captcha plugin which helped greatly in reducing spam for me.
One of the Geeklog Core Developers.
 Quote

Status: offline

Dirk

Site Admin
Admin
Registered: 01/12/02
Posts: 13073
Location:Stuttgart, Germany
Quote by: ChrisN

I am still running v1.4.0sr3.


Which means that you were two security fixes behind. Especially the fixes in 1.4.0sr4 were really important, unless you removed FCKeditor's file manager manually yourself.

bye, Dirk
 Quote

All times are EST. The time is now 11:54 pm.

  • Normal Topic
  • Sticky Topic
  • Locked Topic
  • New Post
  • Sticky Topic W/ New Post
  • Locked Topic W/ New Post
  •  View Anonymous Posts
  •  Able to post
  •  Filtered HTML Allowed
  •  Censored Content