icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » All Things Techy » Site Maintenance » PHP XML-RPC (and Mambo) exploit question

Site Maintenance Program updates, securing your website, creating backups.

Reply
 
LinkBack Thread Tools Search this Thread
Old February 21st, 2006, 11:30 AM   #1 (permalink)
Registered User
Fresh Surpasser
 
Joined in Jul 2005
11 posts
Gave thanks: 0
Thanked 0 times
PHP XML-RPC (and Mambo) exploit question

There's a variety of buzz about a worm targeting PHP XML-RPC and Mambo:

Secunia, which also issued an advisory, said the vulnerability affects version 1.1 of PHP XML-RPC and prior versions. Its advisory recommended upgrading PHP XML-RPC to version 1.1.1.

Mambo wrote on its Web site that it has issued fixes for versions 4.5.3 and 4.5.3h. Those fixes can be downloaded from Mambo's Web site at http://www.mamboserver.com/. It also recommended that users upgrade their software if they have a version earlier than 4.5.3.


My concern is about XML-RPC, but I suspect there are Mambo users here as well. My question is, are we secure from this worm?
huntx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 21st, 2006, 4:53 PM   #2 (permalink)
is scientific.
Resident.
 
David's Avatar
 
Joined in Mar 2004
Lives in fear of Obama.
Hosted on Pass 7
13,117 posts
Gave thanks: 8
Thanked 34 times
Re: PHP XML-RPC (and Mambo) exploit question

Linux worm turns on Mambo and PHP
__________________
Quote:
Originally Posted by removed View Post
Internet Explorer rules.
David is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 21st, 2006, 7:51 PM   #3 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Re: PHP XML-RPC (and Mambo) exploit question

Quote:
Originally Posted by huntx

Mambo wrote on its Web site that it has issued fixes for versions 4.5.3 and 4.5.3h. Those fixes can be downloaded from Mambo's Web site at http://www.mamboserver.com/. It also recommended that users upgrade their software if they have a version earlier than 4.5.3.


My concern is about XML-RPC, but I suspect there are Mambo users here as well. My question is, are we secure from this worm?
If Mambo says they have made fixes, and you use Mambo, then you should upgrade.

We have rules on our router that are blocking similar requests, so everything is ok and we aren't noticing any problems.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 23rd, 2006, 12:39 AM   #4 (permalink)
Registered User
Fresh Surpasser
 
Joined in Jul 2005
11 posts
Gave thanks: 0
Thanked 0 times
Re: PHP XML-RPC (and Mambo) exploit question

If I read you right, the PHP XML-RPC is OK? That was my main concern since I am using Wordpress (hence PHP and XML-RPC) and I couldn't tell what the XML-RPC version was.

Mambo is a bit of a red herring since it gets installed by the user and I shouldn't have mentioned it.
huntx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 23rd, 2006, 1:01 AM   #5 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Re: PHP XML-RPC (and Mambo) exploit question

I just spoke with Paul and I'm pleased to present you with concrete information regarding this.
http://www.surmunity.com/showthread....496#post152496
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old February 24th, 2006, 2:28 PM   #6 (permalink)
Registered User
Fresh Surpasser
 
Joined in Jul 2005
11 posts
Gave thanks: 0
Thanked 0 times
OK, thanks very much
huntx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On