cmsmadesimple.org defacement

cmsmadesimple.org defacement


Posted: September 18, 2007 by Tatu Wikman

The fastest of you noticed the defacement of cmsmadesimple.org site several days ago. The site had been defaced by a script kiddie. The actual script that had been used was r57shell (google). Its a litlle tool one can use to upload / download and query stuff from the server. The script had been there for a while and gone unnoticed as it wasn't used for anything else than removing the log entries from that time :/ One thing is certain, the hole they have used is old, it looks like the FCKEditorX filemanager hole was used, but we cant be sure. We have checked that the release files are intact, and as far as we know no data has been compromised. We are still trying to dig more info about this incident, and are in the process of securing the server up a notch. Sorry about the problems.

Our Partners:
Themeisle EasyThemes