- OpenX Community Forums

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Still Mal-code-injection After Upgrade, Upgrade to 2.8.8 did not solve Problem
KlausKremer
post Nov 20 2011, 06:59 AM
Post #1


Beginner
*

Group: Members
Posts: 1
Joined: 20-November 11
Member No.: 170,845



Dear Comunity,

Our OpenX 2.8.7 was hacked and a Malcode was added to the Database / htmltemplate of the banners. In addition to this, there is a password-promt, when I want to edit the banner-Codes. A lot of sites of our visitors were infected by an iframe directing to coom.in/main.php.
We updated to Version 2.8.8 and deleted all Malcodes in the Database / htmltemplates, but this morning, again the malcode was added.
How can I stop this???
Go to the top of the page
 
+Quote Post
gdl
post Nov 20 2011, 06:10 PM
Post #2


Beginner
*

Group: Members
Posts: 4
Joined: 14-January 10
Member No.: 84,481



Same problem here, anyone been able to solve this?
Go to the top of the page
 
+Quote Post
Marcos Garcia
post Dec 1 2011, 03:41 PM
Post #3


Beginner
*

Group: Members
Posts: 1
Joined: 1-December 11
Member No.: 170,954



QUOTE (gdl @ Nov 20 2011, 07:10 PM) *
Same problem here, anyone been able to solve this?


I have had the same issue, the point is that OpenX 2.8.8 is not vulnerable anymore, but the previos hack created an admin account which were being used to modify the banners, as a regular user would do.

remove the user from the DB and the malicious files he has uploaded

http://blog.openx.org/09/security-update-h...x-installation/
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 

Locations of visitors to this page