Website hack

4 posts by 3 authors in: Forums > CMS Builder
Last Post: October 5, 2009   (RSS)

By cnorthey - October 3, 2009

I have had a couple of sites that use CMS builder come under attack from hackers. It seems that malicious javascript has been added to my PHP files. I have been in contact with the two different hosts for these sites and they both claim it's most likely the CMS that is causing the vulnerability.

The CMS hadn't been updated in about 6 months and I'm wondering in that time if major security updates had been added. Both clients are actually now considering using another CMS package and I'm reluctant to use this program for future clients unless I'm certain CMS builder wasn't the problem or can ensure this won't happen in the future.

Re: [cnorthey] Website hack

By Kenny - October 3, 2009

Here's couple of questions that may help determine what the core problem is.

1. Exactly what files were written to by the hackers? (Most Important)

2. What version of CMS are you using?

3. What did the javascript intend to do and was it successful?


Everything (and I mean EVERYTHING) is hack-able. More important is at what point and why would someone hack your website. As a developer, when you find a hole, you patch it. There is so much more to say and speculate about this, but we really need the answers to the above questions in order speak definitively about the problem.

Please let us know.


Kenny

Re: [cnorthey] Website hack

By Dave - October 5, 2009 - edited: October 5, 2009

Hi cnorthey,

We've never had a site hacked through CMS Builder, and there's never been a security issue that would allow that. So it's almost certainly not CMS Builder.

The usual entry point is open source forums, email form, and blog software. Since these are so common hackers write automated scanners to look for vulnerable versions. Do you clients have any of those scripts on their sites? Even if they are old and no longer used, the hackers scan for the automatically using known paths.

In the 1-2 reports a month we hear of someone getting their site hacked, that has almost always been the cause.

Let me know what you find out or if you need more help tracking it down.
Dave Edis - Senior Developer
interactivetools.com