Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

Why so many people hacked?

Asked Modified Viewed 2,395 times
W
welo
W
welo 10
  • Junior Member, joined since
  • Contributed 11 posts on the community forums.
  • Started 5 threads in the forums
  • Started this discussions
asked
Junior Member

Hi. I just ran across this script via http://www.fabryka.darknation.eu and am always on the lookout for a CMS. The first thing I notice here are dozens of people-getting-hacked threads and no 'Announcements' forum. So how do people know what/when to upgrade or patch? Seems like a neat CMS but do I dare install it anywhere? Is it a phase? I've haven't seen this many hack notifications even at phpbb.
0 replies

8 posts

W
wibix
W
wibix 10
  • Member, joined since
  • Contributed 73 posts on the community forums.
  • Started 15 threads in the forums
answered
Member

the core is save. additional stuff like infusions and mods is what is to be blamed for.
0 replies
M
muscapaul
M
Paul

Time flies like an arrow, fruit flies like banana (Groucho Marx)

Sites: Diptera.info (site owner); Online-Keys.net (site owner); Sciomyzidae.info (site co-owner); muscapaul.com (defunct; site owner)
  • Veteran Member, joined since
  • Contributed 1,075 posts on the community forums.
  • Started 8 threads in the forums
answered
Veteran Member

Quote

welo wrote:
no 'Announcements' forum. So how do people know what/when to upgrade or patch? Seems like a neat CMS but do I dare install it anywhere? Is it a phase? I've haven't seen this many hack notifications even at phpbb.

First of all, when there is an update of the CMS, it will be posted in the news, immediately below the latest threads panel. So not to worry, as soon as you open the main site you will be able to see updates announced.

Secondly, most recent hacking incidents are due to older versions of PHPFusion or faulty infusions. If you use the latest version of PHPFusion and keep up to date with the infusions (most vulnerabilities that have been dealt with will be reported here or on http://www.phpfusion-mods.com) there should be no problem.

Remain the few sites that are being hacked without clear indication why. These indicents can be due to yet unreporeted vulnerabilities, but also compromised security after ealier hacks. If an hacker was able to erase a database, assume that he was also able to extract data from the database. After restoring a hacked site from a back-up can then leave a vulnerable site, even though the scripts are all secure. So, after a hacking incident, make certain all admins from the site change their passwords. This applies to both the site's passwords and the FTP passwords (some people use the same for both, making it easier for hackers).
0 replies
W
welo
W
welo 10
  • Junior Member, joined since
  • Contributed 11 posts on the community forums.
  • Started 5 threads in the forums
  • Started this discussions
answered
Junior Member

Thanks for responding. I'm not trying to start a fight here on my first post, but I hafta be curious. Like I said, I'm always on the lookout for a decent lightweight CMS for project sites or clients. Most of what I've read seems like script kiddie stuff or the usual bonehead admin security precautions (or lack thereof). It's just been awhile since I showed up at a script support site and had the issue leap out at every turn.
0 replies
F
Falk
F
Falk 146
Need help?, Having trouble?
• View our Documentation for Guides, Standards and Functions
• Name and Organize your Topics and Content correctly in the corresponding Forums for best support results
• Attaching Log Files and Screenshots when reporting issues will help
• Provide with an URL to live example if one exists
• Please read the How to Report an Error post
• Please read and comply with the Code of Conduct

(¯·._.·(¯°·._.·°º*[ Project Manager ]*º°·._.·°¯)·._.·¯)
  • Super Admin, joined since
  • Contributed 6,201 posts on the community forums.
  • Started 639 threads in the forums
  • Answered 12 questions
answered
Super Admin

In terms of security, the core of PHP fusion is very stable, by this I mean a basic installation with no added extras such as infusions of any third party modification. The main problem right now is that there are quite a few infusions which have not been checked by any of our team for weaknesses in security. The main reason for this is because we had a fairly limited number of team members.

Right now we are putting together a security awareness team who will be responsible for testing and ensuring that all infusions available from the moddb are 100% secure. What I plan to do is to write a comprehensive guide on how to ensure that the code people write is secure. It comes down to education at the end of the day, when I started writing several years ago I had no experience whatsoever. As I am sure you can imagine I have built up a vast knowledge of how to defend against hacking and exploits.

The one basic rule in coding is that you should never expect any kind of user input to be safe, you have to think that any input or variable which can be altered by any user is malicious. PHP provides a number of functions that can be used to ensure the input is not malicious or is at least safe.

The core of PHP-fusion also has a number of inbuilt functions which can be used to sanitise and check various user input all variables.

On a final note, once a site has been compromised, hacker tends to leave some kind of backdoor in place so that no matter how many times the site is restored, the hacker can get back in much more easily than in the first instance. So it is important to check everything before you reopen a compromised site. The most commonplace to look for any malicious scripts is in the writable folders.

All in all I think you can expect that the security within our community will be increasing dramatically over the next few months especially with the arrival of version 7.
0 replies
Y
Yxos
Y
Yxos 10
Yxos

The best solution is not necessarily a technical solution !
  • Senior Member, joined since
  • Contributed 277 posts on the community forums.
  • Started 28 threads in the forums
answered
Senior Member

Quote

muscapaul wrote:

First of all, when there is an update of the CMS, it will be posted in the news, immediately below the latest threads panel. So not to worry, as soon as you open the main site you will be able to see updates announced.

Right. Therefore any any administrator running a fusion site should check this ste on a regular basis. This is a bit reactive to me.
I would like to se e.g. the news letter (which is active on this site) used to inform about important new releases like 6.01.10. This would be more pro-active I think.
0 replies
W
welo
W
welo 10
  • Junior Member, joined since
  • Contributed 11 posts on the community forums.
  • Started 5 threads in the forums
  • Started this discussions
answered
Junior Member

Quote

Yxos wrote:

Quote

muscapaul wrote:

First of all, when there is an update of the CMS, it will be posted in the news, immediately below the latest threads panel. So not to worry, as soon as you open the main site you will be able to see updates announced.

I would like to se e.g. the news letter (which is active on this site) used to inform about important new releases like 6.01.10. This would be more pro-active I think.


Which is sorta what I was driving at with an 'Announcements' forum. Usually with a script support site that's the first thing I look for, so if I decide to use the script I can subscribe to that forum and be notified of patches and updates. Otherwise I pretty much have to return and check when I think of it, and who knows when that will be? Not seeing a way to subscribe to an entire forum here however, so that might be a moot suggestion in this case.
0 replies
Q
Quartzkyte
Q
www.php-fusion.co.uk/../../images/smiley/cool.gif

Mike
---------------------------------------
Quartzkyte, admin @ French N.S.S.
  • Senior Member, joined since
  • Contributed 404 posts on the community forums.
  • Started 40 threads in the forums
answered
Senior Member

Detail to take into consideration : PHPFusion is widely spread.

Here only, over 14 000 webmasters!

And the victims (I'm one of them) are not so numerous.
The one site of mine that was hacked widely uses infusions.
No problem after upgrade, though.

Besides, the Big Boss (Nick, aka Digitanium) is very security minded. You can rely on PHP Fusion for your sites, pro as well as personal.

On top of it you can buy mugs and apparel to show your support!

It's really a pleasure to use it on a daily basis. I have over a dozen sites now running under PHP Fusion, and this team is really helpful... you'll stick to it when you start :)
0 replies
Y
Yxos
Y
Yxos 10
Yxos

The best solution is not necessarily a technical solution !
  • Senior Member, joined since
  • Contributed 277 posts on the community forums.
  • Started 28 threads in the forums
answered
Senior Member

Quote

Quartzkyte wrote:
Detail to take into consideration : PHPFusion is widely spread.

Here only, over 14 000 webmasters!

And the victims (I'm one of them) are not so numerous.
The one site of mine that was hacked widely uses infusions.
No problem after upgrade, though.

Besides, the Big Boss (Nick, aka Digitanium) is very security minded. You can rely on PHP Fusion for your sites, pro as well as personal.

On top of it you can buy mugs and apparel to show your support!

Yes, you can buy mugs etc, but isn't that getting a bit off topic when we discuss security issues and how to push the information about important upgrades to the webmasters.

I can accept that sending a newsletter to 14.000 users will ocupy Nick's comp for a while and therefore he might choose not to do so.

On the other hand I can't imagine anything that is more important to use the newsletter for.
If not for this, then what is the newsletter good for?

I realize that today there is no newsletter panel on this site where you can subscribe/unsubscribe. I am not sure, but I seem to recall that I pressed the Subscribe button at some point...
Could it be that Nich removed it, realizing that what I just said was true, and therefore took the consequence and removed it ;) If so, hats off!
I have no problem checking this site now and then, but it took some time for me to realize that I ought to.
0 replies

Category Forum

General Discussion

Labels

None yet

Statistics

  • Views 0 views
  • Posts 8 posts
  • Votes 0 votes
  • Topic users 6 members

6 participants

F
F
Falk 146
Need help?, Having trouble?
• View our Documentation for Guides, Standards and Functions
• Name and Organize your Topics and Content correctly in the corresponding Forums for best support results
• Attaching Log Files and Screenshots when reporting issues will help
• Provide with an URL to live example if one exists
• Please read the How to Report an Error post
• Please read and comply with the Code of Conduct

(¯·._.·(¯°·._.·°º*[ Project Manager ]*º°·._.·°¯)·._.·¯)
  • Super Admin, joined since
  • Contributed 6,201 posts on the community forums.
  • Started 639 threads in the forums
  • Answered 12 questions
M
M
Paul

Time flies like an arrow, fruit flies like banana (Groucho Marx)

Sites: Diptera.info (site owner); Online-Keys.net (site owner); Sciomyzidae.info (site co-owner); muscapaul.com (defunct; site owner)
  • Veteran Member, joined since
  • Contributed 1,075 posts on the community forums.
  • Started 8 threads in the forums
W
W
wibix 10
  • Member, joined since
  • Contributed 73 posts on the community forums.
  • Started 15 threads in the forums
Q
Q
www.php-fusion.co.uk/../../images/smiley/cool.gif

Mike
---------------------------------------
Quartzkyte, admin @ French N.S.S.
  • Senior Member, joined since
  • Contributed 404 posts on the community forums.
  • Started 40 threads in the forums
Y
Y
Yxos 10
Yxos

The best solution is not necessarily a technical solution !
  • Senior Member, joined since
  • Contributed 277 posts on the community forums.
  • Started 28 threads in the forums
W
W
welo 10
  • Junior Member, joined since
  • Contributed 11 posts on the community forums.
  • Started 5 threads in the forums
  • Started this discussions

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet