The secure CMS.

Welcome to Geeklog
Friday, September 03 2010 @ 03:28 AM EDT


 Forum Index > Support > General Help New Topic Post Reply
 Possible Hackers
 |  Printable Version
abloch
 March 13 2006 02:33 AM (Read 12639 times)  
Forum Newbie
Newbie

Status: offline

Registered: 06/26/02
Posts: 7

Has anyone noticed any recent hacking attempts, perhaps to take advantage of
the recently patched security hole? The reason I ask is I've seen a couple of odd new user
submissions to my sites, from a couple of email accounts @mail.ru .


 
Profile Email Website PM
Quote
Robin
 March 13 2006 03:07 AM  
Forum Full Member
Full Member

Status: offline

Registered: 02/15/02
Posts: 725

Looks like I'm not alone.
I don't know whether it was hacking or something else and I wouldn't assume that anyone with mail.ru in the email address is a potential hacker however what happened in my case was that on my three geekloged sites there was a registered user evrika (evrika5@mail.ru). Strange coincidence All trhee account were awaiting activation.

The strangest thing was that I opened my browser and entered one of the sites, I was suddenly logged as evrika

Life is full of suprises Anyone else? I'd say everyone checks your new user submissions.


Geeklog Polish Support Team
 
Profile Email Website PM
Quote
starenka
 March 13 2006 03:43 AM  
Forum Newbie
Newbie

Status: offline

Registered: 02/26/06
Posts: 9

my site had this strange login also. by the way - one of my topic admins, can't see his posts when logged in. could this be in some way any coincidence?


 
Profile Email PM
Quote
abloch
 March 13 2006 04:56 AM  
Forum Newbie
Newbie

Status: offline

Registered: 06/26/02
Posts: 7

Evrika5@mail.ru was one of the new users at my sites too. The other suspicious email is valenok55@mail.ru . The reasons that they caught my attention was they both signed up for an account on a site that only uses geeklog for content management and you'd have to be looking for a geeklog site to find the sign up page - any user submissions at that site would be suspicious. Then they signed up at a couple of other sites I maintain.

I haven't yet noticed any odd behavior at my sites, but I'm going to check the logs to see if they have tried anything.


 
Profile Email Website PM
Quote
Nightdude
 March 13 2006 06:20 AM  
Forum Chatty
Chatty

Status: offline

Registered: 09/15/04
Posts: 61

I too, in recent days, had a number of "new users", with an email address ending in .ru.

I deleted these users immediately, as this specific site, a school web community, is of no use to anyone outside our state, let alone, our country.

Just as there are ways, to bypass the usual registration process for email addresses using a specific email suffix, is there a way to lock out specific email suffix, ie..... .ru??

ND


 
Profile Email Website PM
Quote
1000ideen
 March 13 2006 07:49 AM  
Forum Full Member
Full Member

Status: offline

Registered: 08/04/03
Posts: 1176

Well I noticed these two also. They came through:
72.36.180.18 18.180.36.72.reverse.layeredtech.com

I suppose they are potential sleepers / spammer.


The strangest thing was that I opened my browser and entered one of the sites, I was suddenly logged as evrika

@Robin: was that a site runing GL 1.4.0sr2?


 
Profile Email Website PM
Quote
RichardTowler
 March 13 2006 10:37 AM  
Forum Chatty
Chatty

Status: offline

Registered: 03/10/05
Posts: 49

same here...

DorisAxline@yandex.ru
evrika5@mail.ru
valenok55@mail.ru


GameFaction - For All Your Gaming Needs
 
Profile Email Website PM
Quote
Dirk
 March 13 2006 14:39 PM  
Forum Admin
Admin

Status: offline

Registered: 01/12/02
Posts: 12712

Interesting. I see those two mail.ru users on two of my own sites plus another site where I help with administration. But they haven't logged in to any of those sites yet. No such users here on geeklog.net (yet).

My gut feeling is also that those are spammer's accounts, but I have no evidence for or against that.

bye, Dirk

P.S. Don't start nuking your Russian users now just because they happen to use mail.ru ...


 
Profile Email Website PM
Quote
asmaloney
 March 13 2006 14:49 PM  
Forum Full Member
Full Member

Status: offline

Registered: 02/08/04
Posts: 214

I'm suspicious of several accounts [@mail.ru and an alex a.k.a. logos] - all seemingly originating from Russia - because they signed up to multiple [unrelated] sites at roughly the same time but didn't log in to any of them.

Like 1000ideen and Dirk, I suspect they're spammers waiting to strike...


 
Profile Email Website PM
Quote
Anonymous: Rob
 March 14 2006 08:48 AM  


In addtion to finding those two users (on two sites...), I also checked my error log for one of my websites and found that from mid febuary to march someone was repeatedly attempting unsuccessfully to login using names that don't exist, such as "wept", "now80", "love", and "turned4684". Anyone else check thier error log for odd things like this?

-Rob


 
Quote
1000ideen
 March 14 2006 09:14 AM  
Forum Full Member
Full Member

Status: offline

Registered: 08/04/03
Posts: 1176

I think such access attempts are rather normal. I have some every now and again.


 
Profile Email Website PM
Quote
Anonymous: Renski
 March 14 2006 09:46 AM  


Again, the same here.

evrika5@mail.ru
valenok55@mail.ru

No last login dates on any of them.

I've so got to apply the security patch when I get home from work..

I'm a little disappionted with the security problems of late, but Im pleased that Geeklog deals with them out in the open. However, I think it was a mistake to get rid of the blacklist, this is the kind of thing it was supposed to cover.


 
Quote
samstone
 March 14 2006 10:11 AM  
Forum Full Member
Full Member

Status: offline

Registered: 09/29/02
Posts: 808

Me too:

evrika5@mail.ru
valenok55@mail.ru

Sam


 
Profile Email PM
Quote
Anonymous: Renski
 March 14 2006 10:23 AM  


It is fair to say that, without a doubt that, the users evrika5@mail.ru and
valenok55@mail.ru were created using some kind of automated script or program.

Delete the account and block the IP is my advice.


 
Quote
1000ideen
 March 14 2006 10:39 AM  
Forum Full Member
Full Member

Status: offline

Registered: 08/04/03
Posts: 1176

Quote by Renski:
I'm a little disappionted with the security problems of late, but Im pleased that Geeklog deals with them out in the open.


In another thread we tried to establish how popular Geeklog is in regard to other CMS by the number of installations. If we go by the number of hacked sites and compare Mambo and Geeklog then Mambo got no chance.

On the other hand not having the black list seems to make it more difficult to secure GL. One has to have GUS, bad behaviour and Spam-x.

As finding and installing current plugins with GL is a problem in itself I also feel that there should be an easier solution. At least the 3 most important spam plugins should be bundeled or get integrated into GL (spam-x is already integrated).

E.g. Firefox got some addons and it is very easy to install and update them. I`d love this to be tue for GL security plugins too.


 
Profile Email Website PM
Quote
Dirk
 March 14 2006 14:26 PM  
Forum Admin
Admin

Status: offline

Registered: 01/12/02
Posts: 12712

Quote by Renski: However, I think it was a mistake to get rid of the blacklist, this is the kind of thing it was supposed to cover.

Hmm, you seem to be confusing a few things. We didn't "get rid of" MT-Blacklist - the maintainer stopped maintaining it. And it won't help against users registering with your site (how should it?).

bye, Dirk


 
Profile Email Website PM
Quote
ronack
 March 19 2006 08:40 AM  
Forum Full Member
Full Member

Status: offline

Registered: 05/27/03
Posts: 583

It's been a few days since this was talked about but I just want to mention that I have both 1.3.11 and 1.4.0 sr2 sites and it didn't seem to matter, every one of my sites got those same registrants. I turned on User Authoriaztion but I don't want to use that because it could take some time before I authorize the user. I do believe that this is an automated process, hence the need for the visual verification via the image where you have to type in the letters.

Sorry I don't remember the name of it but I'm going to re-look at it.


 
Profile Email PM
Quote
1000ideen
 March 19 2006 08:59 AM  
Forum Full Member
Full Member

Status: offline

Registered: 08/04/03
Posts: 1176

It`s called Capchas and has lately been discussed on the German forum also. It is already a feature request (project site seems to be down at present).

~~~
BTW I found referrer spam this morning:

HEAD index.php Anonymous 70.85.116.229 229.70-85-116.reverse.theplanet.com 19 Mar - 09:58
GET index.php Anonymous 70.85.116.229 229.70-85-116.reverse.theplanet.com 19 Mar - 09:58 http://www.jaja-jak-globusy.com/

I never read this "HEAD" what`s that good for?


 
Profile Email Website PM
Quote
Dirk
 March 19 2006 09:58 AM  
Forum Admin
Admin

Status: offline

Registered: 01/12/02
Posts: 12712

Quote by 1000ideen: GET index.php Anonymous 70.85.116.229 229.70-85-116.reverse.theplanet.com 19 Mar - 09:58 http://www.jaja-jak-globusy.com/

That's a well-know spammer. Add him to your .htaccess and forget about it ...


Quote by 1000ideen: I never read this "HEAD" what`s that good for?

A GET request returns the entire page while HEAD requests only returns the headers. He's a nice spammer, he doesn't want to cause you too much traffic

bye, Dirk


 
Profile Email Website PM
Quote
ronack
 March 19 2006 10:51 AM  
Forum Full Member
Full Member

Status: offline

Registered: 05/27/03
Posts: 583

Yeah Dirk, in fact I just uploaded a Captcha hack for Custom Registration. This thing was SOOOO easy to install. It's a JavaScript version but works great.


 
Profile Email PM
Quote
Content generated in: 3.62 seconds
New Topic Post Reply



 All times are EDT. The time is now 03:28 AM.
Normal Topic Normal Topic
Locked Topic Locked Topic
Sticky Topic Sticky Topic
New Post New Post
Sticky Topic W/ New Post Sticky Topic W/ New Post
Locked Topic W/ New Post Locked Topic W/ New Post
View Anonymous Posts 
Able to post 
Filtered HTML Allowed 
Censored Content