GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   If you run OpenX watch out for this - CRITICAL SECURITY - (https://gfy.com/showthread.php?t=987940)

nikad 09-18-2010 06:56 AM

If you run OpenX watch out for this - CRITICAL SECURITY -
 
http://blog.sucuri.net/2010/09/openx...o-upgrade.html

http://blog.openx.org/09/security-up...8OpenX+Blog%29

Many sites are being reported as malicious by Google, causing traffic loss, etc. Hope you find this useful.

nik

Rick Diculous 09-18-2010 07:15 AM

Yeah, I got 5 of my sites blocked by google this week because I was using openx. they say I distributed badware though openx

Klen 09-18-2010 07:29 AM

This is why i use commercial scripts rather.

strobi 09-18-2010 07:43 AM

Holy shit! checking that out (upgrading)!

TheMaster 09-18-2010 08:02 AM

is this happening to sites running that particular update or for all older OpenX versions?

MaDalton 09-18-2010 08:04 AM

thanks for the info

DWB 09-18-2010 08:52 AM

Quote:

Originally Posted by KlenTelaris (Post 17515017)
This is why i use commercial scripts rather.

Such as?

Dating Port 09-18-2010 09:20 AM

I deleted my OpenX about a year ago.

Thanks for helping that guy out Nikad. I coiuld only see what it was. Not where.

GTS Mark 09-18-2010 09:21 AM

Thanks for the update

LeRoy 09-18-2010 09:29 AM

Better check your sites. This one hurts like a mother fucker!

Klen 09-18-2010 09:35 AM

Quote:

Originally Posted by DirtyWhiteBoy (Post 17515157)
Such as?

Such this shit:
http://smart-scripts.com/?action=smartspots

nikad 09-18-2010 09:42 AM

Glad it was of help! ( as if awms hadnīt been hit hard lately now this :P )

cykoe6 09-18-2010 10:22 AM

Yea this happened to me and it really crushed me. I got my sites which got hit reconsidered by Google and the malware warning taken off but now my whole network is sandboxed. Really painful and costly shit. :(

Vick! 09-18-2010 12:00 PM

Quote:

Originally Posted by KlenTelaris (Post 17515017)
This is why i use commercial scripts rather.

Like commercial ones are immune to security loopholes and vulnerabilities.

:2 cents:

roly 09-18-2010 01:04 PM

Quote:

Originally Posted by Vick! (Post 17515471)
Like commercial ones are immune to security loopholes and vulnerabilities.

:2 cents:

yeah a lot of open source stuff has 100's of geeks going over the code rather than a few employed coders of commercial scripts.

Hawkins 09-18-2010 01:11 PM

OpenX sucks:(

tiger 09-18-2010 04:30 PM

Those fuckers got me, but luckily on only one installation.

CyberHustler 09-18-2010 04:42 PM

I dropped openx right on time... sucks for some of you guys though.

signupdamnit 09-18-2010 04:47 PM

There's an update to fix it...

HomerSimpson 09-18-2010 08:18 PM

openx rocks and this will be solved...

Quote:

Originally Posted by KlenTelaris (Post 17515241)

I have it and I have following problems
- geoip targeting not working for my country
- php includes code not counting hits/clicks
- memcache not working (bad help on this one too)
- banners load slowly the rest of the page, lacking iframe codes...

hdkiller 09-19-2010 02:13 AM

a few days ago (2) just got an update

do your update

Davy 09-19-2010 03:22 AM

That must have been quite a big security hole if it allowed attackers to inject code into the ad fields.

I never liked openX. They include the Pear library in their download which makes the whole thing huge. Many servers already have pear installed. They should just make it a server requirement instead of including it in the download.

nikad 09-19-2010 06:23 AM

The latest update does not completely solve the problem, you must allow only your server ip address to access any files of this script, otherwise they will get in again. I always loved this script, but the security hole has been there for almost a year...that doesnīt make me happy. I will give it a last chance though, but it gets boring :P

stonehammer 09-19-2010 08:38 AM

looks like its time to use simple php scripts like those free random banner scripts


All times are GMT -7. The time now is 12:25 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123