Re: mambo hacked

Federico Sevilla III <[email protected]> Tue, 22 Nov 2005 10:43:54 -0800
Newsgroups gmane.org.user-groups.linux.philippine.newbies
Message-ID <[email protected]>
On Tue, Nov 22, 2005 at 04:42:53AM -0800, alum wrote:
> is mambo hackable?, i have installed mambo after weeks of running it,
> somebody installed a folder on my mambo directory, making a dumpsite
> for his files..
> 
> can this be prevented?, i have port 80 only open on my router because
> of my webserver.
> 
> i tried accessing the access_log and its empty.
> 
> can this be an exploit for apache? how can i prevent this?, i just did
> follow all installation procedures in mambo, i dont know if there are
> security patches.
> 
> or PHP-Nuke is better?

Security is a process, not a product, and although some products are
inherently more secure than others due to more security-conscious design
and implementation, nothing connected to the Internet is truly
hacker-proof. Keeping systems secure is part of the job description of a
system administrator, and part of keeping systems secure is staying on
top of exploit notices and bug fix releases, and upgrading systems
accordingly.

Having said that, there was a recent Mambo remote code execution bug[1]
that was announced on the Full-Disclosure mailing list. And then of
course there's my rant[2] about web application security and PHP in
general, which you may want to consider.

[1] http://archives.free.net.ph/message/20051116.154428.0cbe878d.en.html
[2] http://jijo.free.net.ph/20

Good luck.

 --> Jijo

-- 
Federico Sevilla III : jijo.free.net.ph : When we speak of free software
GNU/Linux Specialist : GnuPG 0x93B746BE : we refer to freedom, not price.
_________________________________________________________
Philippine Linux Users' Group (PLUG) Newbie Mailing List
[email protected] (#PLUG @ irc.free.net.ph)
Read the Guidelines: http://linux.org.ph/lists
Searchable Archives: http://archives.free.net.ph