Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-27, 10:15:22

Author Topic: Question about "Kloxo installations compromised"  (Read 10744 times)

0 Members and 1 Guest are viewing this topic.

Offline delllaptop

  • Junior Member
  • *
  • Posts: 2
  • Karma: +0/-0
    • View Profile
Question about "Kloxo installations compromised"
« on: 2014-01-29, 00:18:02 »
Hi
I want to swith from "kloxo 6.1.12" to "kloxo MR"
But I want to know
Does "kloxo MR" have the below problem?
"http://www.webhostingtalk.com/showthread.php?t=1344003"

Thanks

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: Question about "Kloxo installations compromised"
« Reply #1 on: 2014-01-29, 00:49:19 »
Mustafa, is webcommand.php vulnerable to this exploit?

This is very serious, concerned.  This happened today.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #2 on: 2014-01-29, 04:13:34 »
One reason why Kloxo-MR released is fix security bug (like webcommand.php exploit).
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline zidit

  • Junior Member
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #3 on: 2014-01-29, 06:32:04 »
Can I still using kloxo-api with kloxo-MR?

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #4 on: 2014-01-29, 06:33:13 »
No problem with API in Kloxo-MR.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #5 on: 2014-01-29, 06:34:46 »
Listing of patch/fix/modified related to security issues (mostly from Kloxo Official):

- fix possible sql-injection on login and API
- fix switch 'safe' and 'unsafe' mode)
- disable/remove '/usr/bin/lxsuexec' and '/usr/sbin/lxrestart'
- update suphp config (possible security issue)
- fix lxguard for detect ftp login
- change lxphp+lxlighttpd to php52s+hiawatha
- fix security bug for php-fpm (add open_basedir)
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline zidit

  • Junior Member
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #6 on: 2014-01-29, 06:42:34 »
I am the one who affect by kloxo 6.1.12 compromised. Now I have new vps install fresh kloxo-MR. I need to migrate all data (client/file/db etc.) to new kloxo-MR. I just check folder structure in /home, there are something different. So I'm not sure if I rsync all /home to new one is working? Do you have some instruction to migrate data from the old kloxo to kloxo-MR?

Thank

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #7 on: 2014-01-29, 06:51:36 »
If different VPS, Use backup from Kloxo panel and then restore in Kloxo-MR panel (read warning in https://github.com/mustafaramadhan/kloxo/blob/dev/how-to-install.txt).

If using the same VPS just follow https://github.com/mustafaramadhan/kloxo/blob/dev/how-to-install.txt step B.2, login to panel and 'switch program' (especially web and dns) and 'webserver config' (especially php-branch and php-type).
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline bluearrow

  • Junior Member
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #8 on: 2014-01-29, 07:59:24 »
Iniz hosting service asked everyone to move from Kloxo to another panel and I wonder if they counts Kloxo-MR as Kloxo too.

Is there anything we must do from those patch/fix/modified listed ? I have do running vps with Kloxo-MR and I haven't had a single problem month. I hate to mess anything.

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #9 on: 2014-01-29, 08:29:39 »
Iniz hosting service asked everyone to move from Kloxo to another panel and I wonder if they counts Kloxo-MR as Kloxo too.

Is there anything we must do from those patch/fix/modified listed ? I have do running vps with Kloxo-MR and I haven't had a single problem month. I hate to mess anything.

Try changing Kloxo-MR port from 7777/7778 to others (let say 8777/8778). Possible with this trick, port scanning to 7777/7778 will fail.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline zidit

  • Junior Member
  • *
  • Posts: 14
  • Karma: +0/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #10 on: 2014-01-29, 09:11:55 »
Iniz hosting service asked everyone to move from Kloxo to another panel and I wonder if they counts Kloxo-MR as Kloxo too.

Is there anything we must do from those patch/fix/modified listed ? I have do running vps with Kloxo-MR and I haven't had a single problem month. I hate to mess anything.

Try changing Kloxo-MR port from 7777/7778 to others (let say 8777/8778). Possible with this trick, port scanning to 7777/7778 will fail.

Where can I change this? :)

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #11 on: 2014-01-29, 09:14:33 »
Find out 'Port Config'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline bluearrow

  • Junior Member
  • *
  • Posts: 29
  • Karma: +0/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #12 on: 2014-01-29, 09:54:06 »
Where can I change this? :)

Goto Kloxo admin pannel and search for Port Config


Port changing suggest is great. That's one way a hacker would find a Kloxo hosted server. I think every small thing like that can help. ))

Offline cmdman

  • Senior Member
  • *
  • Posts: 298
  • Karma: +1/-0
    • View Profile
Re: Question about "Kloxo installations compromised"
« Reply #13 on: 2014-01-29, 11:44:31 »
any help

 i got  mail from my hoster to turn off kloxo any help please i have 5 vps and 1 dedi server

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Question about "Kloxo installations compromised"
« Reply #14 on: 2014-01-29, 11:50:33 »
@cmdman,

All Kloxo security issue already fixed in Kloxo-MR!. Ask to your provider for 'how about Kloxo-MR'.

Some VPS providers already approve where 'Kloxo-MR is fine'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.034 seconds with 19 queries.

web stats analysis