Jump to content

Clay.io is under attack...


Raiper34
 Share

Recommended Posts

Again, I apologize for this happening. After having some time to look into it, here's a bit of a mini post mortem:

 

An individual used an exploit in the forum software we're using (Vanilla Forums) to upload a php file. He then used that file to prepend a header() redirect to a php file that serves as a router. It redirected to a malicious file that I can only assume was some sort of bitcoin miner (the site URL implied that it was bitcoin related). Vanilla Forums released a security update a few weeks ago (http://vanillaforums.org/discussion/25668/dec-2013-security-update-2-0-18-10-and-2-1b2), but unfortunately we had not upgraded (installing the update now).

 

Lessons learned: be smarter with file permissions and more careful with 3rd party software.

Link to comment
Share on other sites

Its somehow always the forums... >_<

How about outsourcing the forums on a different server, or - if you have root access to your server, put the board software in a separate folder and map that folder in apache to a specific subdomain. That should prevent leaking data from the board over to the rest of the project.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...