icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » All Things Techy » Site Maintenance » TopSites Warning

Site Maintenance Program updates, securing your website, creating backups.

Reply
 
LinkBack Thread Tools Search this Thread
Old June 11th, 2007, 5:46 PM   #1 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
TopSites Warning

In the past week there have been issues on several servers which point back to TopSites installations. TopSites is a popular site ranking script which you may be familiar with.

Even the website for TopSites seems to be suffering from attack, I am unable to connect successfully:
Quote:
Warning: mysql_connect() [function.mysql-connect]: Can't connect to local MySQL server through socket '/tmp/mysql.sock' (11) in /home/aardvark/public_html/index.php on line 5
Can't connect to local MySQL server through socket '/tmp/mysql.sock' (11)
The problem we see is that many different IPs (most are hijacked PCs located in Turkey, used as bot networks) are hammering these TopSites directories, acting as mini DoS attacks against those servers. The last security advisory for TopSites was last year, but apparently it remains unpatched. This does not give us much faith in the developers - it could have been fixed a long time ago, then we would not be dealing with this problem now.

The bottomline is that we are forced to disable the affected directories as we find them. We do recommend replacing this script with a similar one.
We are likely disabling TopSites in all Fantastico panels.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 11th, 2007, 5:49 PM   #2 (permalink)
Dan
Staff of Surpass
Super #1
 
Dan's Avatar
 
Joined in Apr 2007
2,744 posts
Gave thanks: 152
Thanked 184 times
Is it that people are sending tons of connections to the topsites to try to increase their ranking on them or just trying to bring down the topsites?
__________________
D4nz Net - Surpass Help Desk - NES Forever
Use the thanks button. It works!
AIM: dansorl
Dan is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 11th, 2007, 5:59 PM   #3 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
The bot networks are trying to access the directories to hack into the accounts since they still have the vulnerability from last year. http://secunia.com/advisories/19911
They are not going to get in due to our server configuration, but them trying is enough harm to Apache's stability.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 11th, 2007, 6:25 PM   #4 (permalink)
Surpass Fan
On a golden path...
 
Neil's Avatar
 
Joined in Oct 2004
Lives in UK
361 posts
Gave thanks: 6
Thanked 14 times
Could this result in CPU ratings clearing 17, mail refusing connections and servers such as Pass62 generally reacting very slowly?
__________________
D17/D21/P59/P62/VPSX - "Faith can move mountains" (Faiths a big girl....) - I'm not paranoid, I know they are out to get me!
Neil is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 11th, 2007, 6:39 PM   #5 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
On Pass62 specifically I do not see any requests for TopSites directories. What I do see is a few forums taking up some load.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 11th, 2007, 7:08 PM   #6 (permalink)
Surpass Fan
On a golden path...
 
Neil's Avatar
 
Joined in Oct 2004
Lives in UK
361 posts
Gave thanks: 6
Thanked 14 times
OK thanks.
__________________
D17/D21/P59/P62/VPSX - "Faith can move mountains" (Faiths a big girl....) - I'm not paranoid, I know they are out to get me!
Neil is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 12th, 2007, 1:32 AM   #7 (permalink)
is scientific.
Resident.
 
David's Avatar
 
Joined in Mar 2004
Lives in fear of Obama.
Hosted on Pass 7
13,113 posts
Gave thanks: 8
Thanked 34 times
Actually, it's because my blog is listed on all of these, and people are just visiting a lot.
__________________
Quote:
Originally Posted by removed View Post
Internet Explorer rules.
David is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 15th, 2007, 3:59 PM   #8 (permalink)
Surpass Fan
Excelling Contributor
 
Joined in Dec 2005
Lives in my computer
Hosted on pass86'd
660 posts
Gave thanks: 56
Thanked 14 times
ok, here is my question on topsites, I am wondering which software you are talking about and is there a better topsites software then others that would follow more into what you are thinking about Kayla..

or you would rather not have any at all..

I have one, but it sits dead at the moment, I wont say the address here, but I will say it in a support ticket if need be...

I am curious as to which software is better or worse and which ones are not patched, or should I just can the idea...

thx

MJ
__________________

panache is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old June 15th, 2007, 6:15 PM   #9 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
The one in question here, Aardvark TopSites is currently not patched.

I think it's one of the most popular scripts out there due to it being packed with Fantastico.. and since so many servers are equipped with cPanel.

As I browse around for different topsites scripts, it is pretty disappointing. Many are paid-only scripts (which means updates and support) but free ones are outdated.. such as:
http://www.evo-dev.com/products/evotopsites (2005)

I am looking towards the can here...
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On