<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenX Consultant Erik Geurts<title> &#187; security fix</title>
</title>
	<atom:link href="http://www.openxconsultant.com/blog/tag/security-fix/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.openxconsultant.com</link>
	<description>Offering support, consulting, and training</description>
	<lastBuildDate>Wed, 01 Sep 2010 11:53:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Attacks on OpenX v2.8.2 installations reported</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/</link>
		<comments>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 09:00:04 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445</guid>
		<description><![CDATA[Starting Saturday, April 10, 2010, users of OpenX v2.8.2 have begun to experience problems with their ad servers that have now been traced back to the security vulnerability that I wrote about back in December of 2009. First symptoms: statistics disappeared The first symptoms is that the statistics in OpenX disappear. I&#8217;ve seen reports of [...]]]></description>
			<content:encoded><![CDATA[<p>Starting Saturday, April 10, 2010, users of OpenX v2.8.2 have begun to experience problems with their ad servers that have now been traced back to the <a href="http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/" target="_self">security vulnerability</a> that I wrote about back in December of 2009.</p>
<p><span id="more-445"></span></p>
<h2>First symptoms: statistics disappeared</h2>
<p>The first symptoms is that the statistics in OpenX disappear. I&#8217;ve seen reports of people mentioning this on the OpenX forums, and some people have also contacted me directly. Luckily, the statistics aren&#8217;t really gone from the database, and ad delivery continues to function without problem. This was confirmed when inspecting the database and looking at the tables that store the statistics.</p>
<h2>Cause: hacks of old versions</h2>
<p>While investigating one of these problematic OpenX installations, fellow <a title="OpenX consultant Matteo Beccati" href="http://www.beccati.com/" target="_blank">OpenX consultant Matteo Beccati</a> discovered that it had been attacked, abusing a vulnerability in OpenX v2.8.2 that has been fixed a long time ago. Unfortunately, not everyone has taken the time to upgrade yet, leaving their systems vulnerable to attacks like this one.</p>
<p>It was found that the attacker uses this security vulnerability to insert an additional administrator account. Next he uses this login to upgrade the OpenX plugin that takes care of the available banner types. The plugin he injects contains malicious code that creates a backdoor into the server. As a side effect, the attack creates some entries in the database, leading to the disappearance of the on-screen statistics.</p>
<p>From the logs that have been found, this appears to be an automated attack. The attacks that have been investigated are all originating from the same IP address.</p>
<h2>Remedy: upgrade</h2>
<p>For someone running OpenX v2.8.2 or older who hasn&#8217;t been infected yet, the best course of action is to upgrade to a more recent version of OpenX as soon as possible. If it takes a while to prepare and plan for this, then meanwhile I would recommend removing the install.php and install-plugins.php files in the &#8216;www/admin&#8217; folder of your OpenX installation.</p>
<p>If a system has been attacked already, an upgrade is not going to fix this problem, since the modified plugin will be migrated to the new version, along with any changes in the database. This will have to be cleaned first.</p>
<h3>Update</h3>
<p>In later reports of the same kind of hack, the &#8216;missing statistics&#8217; issue no longer occurred. It appears that the hacker has changed this element. However, the malicious code is still getting injected. The first time people notice problems is when their site or the ad server is reported as as containing malware by Google&#8217;s Safe Browsing program.</p>
<p>Not only OpenX v2.8.2 is vulnerable to this problem, the same applies to v2.8.0 and v2.8.1.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>OpenX Ad Server v2.8.3 released &#8211; Security Fix!</title>
		<link>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/</link>
		<comments>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 10:47:53 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Upgrading]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=287</guid>
		<description><![CDATA[A security problem has been discovered in OpenX Ad Server v2.8.2, enabling anyone to log in as an Administrator. This is obviously an very serious problem, because it renders any OpenX Ad Server vulnerable. An emergency fix has been developed and released as OpenX Ad Server v2.8.3. The new version is available for immediate download [...]]]></description>
			<content:encoded><![CDATA[<p>A security problem has been discovered in OpenX Ad Server v2.8.2, enabling anyone to log in as an Administrator. This is obviously an very serious problem, because it renders any OpenX Ad Server vulnerable.</p>
<p>An emergency fix has been developed and released as <strong>OpenX Ad Server v2.8.3</strong>. The new version is available for <a href="http://www.openx.org/ad-server/download" target="_blank">immediate download</a> at the OpenX website. The <a href="http://blog.openx.org/12/security-matters-2/" target="_blank">OpenX Blog provides background information</a> and tips for security precautions.</p>
<p><em>Update April 13, 2010: it appears that <a href="http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/">an exploit for the vulnerability in OpenX v2.8.2</a> is making the rounds on the internet, infection these old versions with a back door and breaking the display of the on-screen statistics.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (user agent is rejected)
Database Caching 4/14 queries in 0.021 seconds using disk

Served from: www.openxconsultant.com @ 2010-09-08 07:30:37 -->