Skip to Content Skip to Menu

Demo website hacked ?

  • activha
  • activha
  • OFFLINE
  • Posts: 2326
  • Thanks: 117
  • Karma: 13
3 years 5 months ago #324795 by activha
Demo website hacked ? was created by activha
Hello guys

It seems like your demo site has been hacked.
Each click on an activity opens a pop up with porn ads or others

Please Log in or Create an account to join the conversation.

  • beat
  • beat
  • OFFLINE
  • Posts: 2169
  • Thanks: 463
  • Karma: 352
3 years 5 months ago - 3 years 5 months ago #324796 by beat
Replied by beat on topic Demo website hacked ?
Hi activha,
Thanks for the heads-up!

I have manually triggered a site refresh this morning after your post.

Looking at the logs, it does not look like the demo site got hacked, but that a spammer took advantage of the demo super-administrator account to change the site to his liking!

The site automatically refreshes (resets to initial state) every few hours, we thought that this would be discouraging enough to us it for spam.

I have now changed the setting refresh it on an hourly base, and we will restrict further the demo super-admin account. Having a full super-admin account available for demo on a demo site is anyway probably not the best idea in town. A restricted administrator account that also filters HTML content is sufficient.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info
Last edit: 3 years 5 months ago by beat. Reason: spelling error

Please Log in or Create an account to join the conversation.

  • beat
  • beat
  • OFFLINE
  • Posts: 2169
  • Thanks: 463
  • Karma: 352
3 years 5 months ago #324798 by beat
Replied by beat on topic Demo website hacked ?
I have now changed the demo administrator account of the demo site from Super-Administrator to Administrator, and drastically limited its rights to CB-specific area. I have also removed his right to edit Joomla articles, menus, templates and modules, as well as any non-directly CB-related items. Finally, I have activated full Joomla HTML filtering for it.

This should seriously limit the possible missuse of the admin interface to "hack" the content or insert Javascript popups.

The demo site will reset itself / refresh to the new version automatically in 15 minutes from now.

Thanks again for your heads-up.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in or Create an account to join the conversation.

  • activha
  • activha
  • OFFLINE
  • Posts: 2326
  • Thanks: 117
  • Karma: 13
3 years 5 months ago #324807 by activha
Replied by activha on topic Demo website hacked ?
You're welcome, glad to be useful ;-)

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48424
  • Thanks: 8274
  • Karma: 1443
3 years 5 months ago #324813 by krileon
Replied by krileon on topic Demo website hacked ?
Admin demo user had too many permissions. We've significantly limited it now. Hopefully won't happen again. We wanted to give a nice and complete backend demo, but we'll have to limit it greatly now. Spammers just can't let us have anything can they.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum