- OpenX Community Forums

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Upgrade To 2.8.8 Gives Openx Admin Access?
amp3dmoshpit
post Nov 7 2011, 01:57 AM
Post #1


Member
***

Group: Members
Posts: 54
Joined: 14-March 03
Member No.: 344



I upgraded to Openx 2.8.8 last night and was going though thinks to make sure I didn't lose any settings when I came across the Admin Access page. Yesterday at the time of my upgrade a new admin account was created called 'openx-manager' This account has full admin privileges. What is this account for and why was it created? What happens if I delete it?

openx-manager admin@openx-team.org OpenX Team 2011-11-05 08:47:04
Go to the top of the page
 
+Quote Post
Carl0s2
post Nov 7 2011, 02:30 PM
Post #2


Beginner
*

Group: Members
Posts: 5
Joined: 7-April 11
Member No.: 166,631



QUOTE (amp3dmoshpit @ Nov 7 2011, 01:57 AM) *
I upgraded to Openx 2.8.8 last night and was going though thinks to make sure I didn't lose any settings when I came across the Admin Access page. Yesterday at the time of my upgrade a new admin account was created called 'openx-manager' This account has full admin privileges. What is this account for and why was it created? What happens if I delete it?

openx-manager admin@openx-team.org OpenX Team 2011-11-05 08:47:04


This happened to me without upgrading, I was still on 2.8.7. I deleted the admin account and blocked access to adserver.openx.org (the apparent source of the change). I assumed this was a hack attempt so I restored to last known good backup.

If this is actually legitimate then please let us know.
Go to the top of the page
 
+Quote Post
moresearch
post Nov 17 2011, 10:41 PM
Post #3


Member
**

Group: Members
Posts: 11
Joined: 18-September 11
From: Switzerland
Member No.: 170,143



I got this strange Administrator Account too.
Till November 6 2011 i did not had such a account !

Strange thing is also that i was able somehow to Login into the OpenX-Market webpage direct by using my adserver to see how much Money i really earned on the OpenX-Market itself.

Now it show only the Quality Ad Tool when i log into OpenX_Market.

At nearly Same Time also my Ads were getting displayed very Strange. Asking me if anybody changed and Hi Jacked my good going Advertising which were booked for my Website on my Adserver by some Remote Control !

http://forum.openx.org/index.php?s=&sh...st&p=307389

The very Big Problem is also that the email address admin@openx-team.org dont even work or it exist on the Net.
It is a fake address !

I will delete this very Specious Admin account !
Go to the top of the page
 
+Quote Post
monokuro
post Nov 18 2011, 07:49 AM
Post #4


Beginner
*

Group: Members
Posts: 8
Joined: 16-April 11
Member No.: 167,721



That account is automatically added when you install the "OpenX Marketplace" plugin. If you remove it, the account is also removed.

I guess it's an internal account so it can manage the Marketplace ads that get shown on the sites?
Go to the top of the page
 
+Quote Post
moresearch
post Nov 23 2011, 03:48 AM
Post #5


Member
**

Group: Members
Posts: 11
Joined: 18-September 11
From: Switzerland
Member No.: 170,143



And why does this strange Account then use a non functional non registered fake web domain email ?

I removed the Account now since more than a Day and still all works great with the Delevering of the Advertising.

I see also the Money in my Stats that i earned.

The Only thing that does not work is that for some strange reason i am not able
to see how Much Money i Earned direct in openx.com.

Before i discovered this Account i was able to login from my Adserver direct into
openx.com and look if the Amount of Money i earned with my Adserver is same with the Amount of the OpenX Market.
Go to the top of the page
 
+Quote Post
wfsfan
post Nov 25 2011, 05:03 AM
Post #6


Beginner
*

Group: Members
Posts: 3
Joined: 9-September 09
Member No.: 45,941



If you have this account you have been hacked (most likely before the upgrade).

What you want to do is IP/password protect using htaccess your entire admin directory to prevent any future attacks.

Then scan you're database for malware javascript.

Go to the top of the page
 
+Quote Post
Necroncon
post Dec 19 2011, 12:20 PM
Post #7


Beginner
*

Group: Members
Posts: 2
Joined: 9-December 10
Member No.: 154,081



QUOTE (wfsfan @ Nov 25 2011, 05:03 AM) *
If you have this account you have been hacked (most likely before the upgrade).

What you want to do is IP/password protect using htaccess your entire admin directory to prevent any future attacks.

Then scan you're database for malware javascript.


Is this true, is the adserver being hacked or is it an email adres for the openx market plugin?

Please let me know
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 

Locations of visitors to this page