icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » All Things Techy » Site Maintenance » Attention: EXPLOIT : PHP Nuke Users

Site Maintenance Program updates, securing your website, creating backups.

Reply
 
LinkBack Thread Tools Search this Thread
Old November 23rd, 2004, 8:47 PM   #1 (permalink)
Searcher
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,699 posts
Gave thanks: 943
Thanked 806 times
Exclamation Attention: EXPLOIT : PHP Nuke Users

For those of you using PHP Nuke:

More than half of our spam/blacklisting problems derive from PHP Nuke installs on our customers' websites. Older versions of PHP Nuke can be used to send out spam. There is nothing we can do for you to prevent this from happening. Only your cooperation will help us.

We ask that everyone make sure to use ONLY the latest version of PHP Nuke.
You can download it here:
http://phpnuke.org/modules.php?name=...download&cid=1

We also strongly recommend that you add the module, Sentinel. You can read about the great features and download it here:
http://www.nukeresources.com/downloa...eSentinel.html

It is very important that you use the latest version. If your account is used to send out spam, it will be temporarily suspended and you will be required to have the latest version installed.


These sites below are very good to keep yourself updated with:

http://www.nukefixes.com/
http://www.nukescripts.net/
__________________
Follow Surpass on Twitter and Facebook
Check out interesting finds on the Surpass Blog
.... it's coming.


Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old March 20th, 2005, 11:43 PM   #2 (permalink)
Searcher
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,699 posts
Gave thanks: 943
Thanked 806 times
On some newer servers, the last place I thought I would see PHP Nuke webmail again ... there has been some extensive spamming going on.

This is a reminder: We do NOT allow the WebMail module of PHP Nuke. This can be exploited.

No version of PHP Nuke is available with that module officially.
http://www.phpnuke.org/modules.php?n...ticle&sid=7081

As I understand, there are WebMail plug-ins available from 3rd party programmers. These are NOT allowed.


The image attached is an email that was just going out of SH59. The scammers had created multiple usernames in a Surpass customer's PHP Nuke site and were exploiting PHP Nuke WebMail to send out hundreds of emails. They were doing so well that I've already got SpamCop reports on these messages.

We will disable any /modules/WebMail/ folder on all of our servers. A script is running again that we ran last November and December that goes through all servers and does this on a weekly basis.
Attached Images
File Type: gif scam.gif (12.5 KB, 10 views)
Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On