Go Back   Pligg CMS Forum > Announcements > Pligg News

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-09-2007, 03:57 AM
dollars5's Avatar
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,154
Thanks: 290
Thanked 266 Times in 177 Posts
Exclamation Alert!!: Some hackers/spammers trying to attempt the old password reset flaw!

Recently on 5 of the Pligg based sites maintained by us; we noticed that there have been some sort of attack on the password reset to "Password" attempts - it was a security bug and was fixed with 9.6 beta and detailed steps to protect are discussed at Security Vulnerability and Security Vulnerability Part 2

Since these sites had the patched applied nothing serious other than all users received a password reset process e-mail (unless they hit that link in the e-mail the password will not get reset and they had not initiated it - fortunately they all forwarded this to ) - thanks Ash for fixing.

Not sure how many other sites were attempted on this. Some log study revealed that the IP that did attempt to access this page /login.php did infact take a referrer from those site's announcements listed at http://forums.pligg.com/my-pligg-site/ the IPs that were involved were:
66.98.212.79, 66.199.251.90, 62.231.243.137, 125.212.68.173, 68.36.148.91 in the order of number of requests.

So if you have your site listed - here or in Pligg directories, it is advisable to use the patches as outlined above.

Just thought of sharing it in here as it might be an alert to people who did not update their site code.
Reply With Quote
  #2 (permalink)  
Old 07-09-2007, 04:01 AM
Constant Pligger
 
Join Date: Apr 2007
Posts: 1,071
Thanks: 53
Thanked 25 Times in 23 Posts
I´m not related, nevertheless thank you for helping the community not to suffer any harm from these bastards!
Reply With Quote
  #3 (permalink)  
Old 07-09-2007, 04:13 AM
dollars5's Avatar
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,154
Thanks: 290
Thanked 266 Times in 177 Posts
more investigation links them to spammer addresses - still investigating for an IP ban on those addresses also harvesting more such spammer IPs. will keep this updated.
Reply With Quote
  #4 (permalink)  
Old 07-09-2007, 04:16 AM
Constant Pligger
 
Join Date: Apr 2007
Posts: 1,071
Thanks: 53
Thanked 25 Times in 23 Posts
Have you tried reverse DNS? Then you could complain at the provider.
Reply With Quote
  #5 (permalink)  
Old 07-09-2007, 04:27 AM
dollars5's Avatar
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,154
Thanks: 290
Thanked 266 Times in 177 Posts
Am doing that with dnsstuff.com to gather a more detailed info before we file any spam reports to their ISPs.
Reply With Quote
  #6 (permalink)  
Old 07-09-2007, 04:54 AM
Constant Pligger
 
Join Date: Apr 2007
Posts: 1,071
Thanks: 53
Thanked 25 Times in 23 Posts
Would have been my choice also. Did you know that there is an dnsstuff extension for firefox (Mycroft Project: Sherlock & OpenSearch Search Engine Plugins) ?
Reply With Quote
Reply

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Password reset issue webdevil2003 Bug Report 8 08-29-2008 12:48 PM
User Password Reset help!! auctionguy Installation and Upgrade Help 5 10-14-2007 10:52 AM
[SOLVED] Password Reset Unknown Bug Report 11 09-14-2007 01:45 AM
Password Reset Unknown General Help 1 09-01-2007 02:34 AM
Password always gets reset to 'password' ? unohoo General Help 7 09-24-2006 11:20 AM


Search Engine Friendly URLs by vBSEO 3.2.0