ROX web-site hacked

Thomas Leonard <[email protected]> Sun, 30 Dec 2012 13:10:03 +0000
Newsgroups gmane.comp.desktop.rox.user,gmane.comp.desktop.rox.devel
Message-ID <CAG4opy90vOys809mRHUOcn33og7euH+m4SFRqr1S6n=R+nhVhQ@mail.gmail.com>
I got an email today from Google to say that the ROX web-site
contained spammy links. On investigation, I found some suspicious
files on the server (a .htaccess which redirected things to
"image.php", which contained a load of obfuscated PHP). The oldest
ctime was Nov 11, 2012.

This isn't very surprising; Drupal has regular security
vulnerabilities and I don't have time at the moment to keep it
properly patched. I have therefore exported the whole site to static
HTML (using httrack). I also moved it back to sourceforge.net since,
being static, database performance is no longer an issue:

  http://rox.sourceforge.net/desktop/

There should be no risk of anyone having installed malicious software
from the site, since 0install always ensures the GPG signatures are
correct when downloading software (and the signing key is not on the
server).

I will probably move ROX-Filer over to github at some point, along
with anything else that needs updating in the future.

Hopefully that's the end of it, but let me know if you spot anything suspicious.


-- 
Dr Thomas Leonard        http://0install.net/
GPG: 9242 9807 C985 3C07 44A6  8B9A AE07 8280 59A5 3CC1
GPG: DA98 25AE CAD0 8975 7CDA  BD8E 0713 3F96 CA74 D8BA

------------------------------------------------------------------------------
Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS,
MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current
with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft
MVPs and experts. ON SALE this month only -- learn more at:
http://p.sf.net/sfu/learnmore_123012