Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
mommacude Offline
Member
 
Posts: 63
Join Date: Sep 2004
Site Hacked?! - 22-11-2006, 08:00 PM

When I go to my site www.cjcustomers.com I have this message that says:

"Hacked By UserMode ==> ThaiShadow.com "

Has anyone ever seen this? I'm a little freaked out not sure what's going on.
   
Reply With Quote
  (#2) Old
Racked Hosting Offline
Member
 
Posts: 345
Join Date: Mar 2006
Location: Manipal
22-11-2006, 08:34 PM

The version 3.00.32 has some vulnerabilities. I advice you to immediately upgrade.
   
Reply With Quote
  (#3) Old
Raghav Arora Offline
Team Leader (Support)
 
Raghav Arora's Avatar
 
Posts: 185
Join Date: Apr 2005
22-11-2006, 09:47 PM

Please upgrade your helpdesk immediately and I will ping Varun to post you an update on this issue.


Raghav Arora (raghav.arora ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#4) Old
Racked Hosting Offline
Member
 
Posts: 345
Join Date: Mar 2006
Location: Manipal
22-11-2006, 10:04 PM

Also, please change your passwords as well. It's highly possible, they got your passwords and edited the templates.
   
Reply With Quote
  (#5) Old
bear Offline
Community Moderator
 
Posts: 674
Join Date: Jan 2005
22-11-2006, 10:23 PM

Someone point me to the announcement about 3.00.32 being vulnerable, and if it requires a full update or if there's a patch?
   
Reply With Quote
  (#6) Old
internut33 Offline
Member
 
Posts: 177
Join Date: Apr 2004
22-11-2006, 10:27 PM

good question... ? owch.


--------------------------------------------
Love me an eSupport
--------------------------------------------
   
Reply With Quote
  (#7) Old
Raghav Arora Offline
Team Leader (Support)
 
Raghav Arora's Avatar
 
Posts: 185
Join Date: Apr 2005
22-11-2006, 11:17 PM

Can you forward me your Apache access_logs to raghav.arora [at] kayako.com, I would like to review them and confirm whether the exploit was through eSupport in first place.

Regards,

Raghav Arora


Raghav Arora (raghav.arora ]at[ kayako.com)
----------------------------------------------------------------
---
   
Reply With Quote
  (#8) Old
Racked Hosting Offline
Member
 
Posts: 345
Join Date: Mar 2006
Location: Manipal
23-11-2006, 08:49 AM

Quote:
Originally Posted by bear
Someone point me to the announcement about 3.00.32 being vulnerable, and if it requires a full update or if there's a patch?
http://www.securityfocus.com/bid/20954

However, I don't think that was the cause for this person's site being hacked.
   
Reply With Quote
  (#9) Old
supportskins Offline
Senior Member
 
supportskins's Avatar
 
Posts: 3,962
Join Date: Aug 2006
Location: Mumbai, India
23-11-2006, 10:15 AM

This is the first time I have come across anything like this
   
Reply With Quote
  (#10) Old
Racked Hosting Offline
Member
 
Posts: 345
Join Date: Mar 2006
Location: Manipal
23-11-2006, 11:47 AM

It's not a huge security flaw, so don't worry
   
Reply With Quote
  (#11) Old
bear Offline
Community Moderator
 
Posts: 674
Join Date: Jan 2005
23-11-2006, 11:57 AM

That's the only security flaw? If that's truly all it is, it's nothing to get worked up over...needs patching, sure, but not terribly scary. I agree it seems unlikely to be the cause of the OPs hack.
   
Reply With Quote
  (#12) Old
Racked Hosting Offline
Member
 
Posts: 345
Join Date: Mar 2006
Location: Manipal
23-11-2006, 12:00 PM

It's already patched of course, it just exists with 3.00.32, I guess.
   
Reply With Quote
Reply

Tags
hacked, site

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hosted Site DB import into Owned Site christinasc SupportSuite, eSupport and LiveResponse 18 01-02-2007 09:07 AM
Integration of SupportSuite News with Web Site Joseph SupportSuite, eSupport and LiveResponse 2 03-08-2006 06:39 AM



Powered by vBulletin® Version 3.7.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Help desk software by Kayako.


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48