LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > litespeed hacked?

Reply
 
Thread Tools Display Modes
  #11  
Old 06-13-2010, 08:07 AM
DanEZPZ DanEZPZ is offline
Senior Member
 
Join Date: Jul 2009
Posts: 55
I just had an email from George saying it's being looked in to and they'll post a fix later today if they're able to replicate it.
Reply With Quote
  #12  
Old 06-13-2010, 08:11 AM
cmanns cmanns is offline
Senior Member
 
Join Date: Jun 2010
Posts: 100
Quote:
Originally Posted by DanEZPZ View Post
I just had an email from George saying it's being looked in to and they'll post a fix later today if they're able to replicate it.
Now I like to hear that
Reply With Quote
  #13  
Old 06-13-2010, 08:20 AM
anewday anewday is offline
Senior Member
 
Join Date: Nov 2007
Location: New York
Posts: 723
Uh oh. So, there's only one mod_security rule?

Are there any serious bugs in 4.0.14? It still haven't been activated in the auto upgrader in the web console.
Reply With Quote
  #14  
Old 06-13-2010, 08:21 AM
DanEZPZ DanEZPZ is offline
Senior Member
 
Join Date: Jul 2009
Posts: 55
It also affects 4.0.11,12 and 13 so it's not just a .14 thing.
Reply With Quote
  #15  
Old 06-13-2010, 08:38 AM
cmanns cmanns is offline
Senior Member
 
Join Date: Jun 2010
Posts: 100
Quote:
Originally Posted by anewday View Post
Uh oh. So, there's only one mod_security rule?

Are there any serious bugs in 4.0.14? It still haven't been activated in the auto upgrader in the web console.
I've not had a single issue that I can point out that is with 4.0.14, I used 4.0.13 for a few days or so when we fire'd up LiteSpeed on our cpanel box may 29th and back around Feb, .14 just seemed better
Reply With Quote
  #16  
Old 06-13-2010, 10:09 AM
Lauren Lauren is offline
LiteSpeed Staff
 
Join Date: Jul 2003
Location: New Jersey, USA
Posts: 99
Default please try to test latest build

Hi,

4.0.15 for linux version has been built and ready for download.
http://www.litespeedtech.com/litespe...lease-log.html

please help test to confirm the issue is resolved. just go to download page and replace 4.0.14 with 4.0.15 in url.

Thanks,
Lauren
Reply With Quote
  #17  
Old 06-13-2010, 10:22 AM
anewday anewday is offline
Senior Member
 
Join Date: Nov 2007
Location: New York
Posts: 723
Thanks for the quick fix.
Reply With Quote
  #18  
Old 06-13-2010, 10:57 AM
DanEZPZ DanEZPZ is offline
Senior Member
 
Join Date: Jul 2009
Posts: 55
Installed and tested and it seems to work perfectly, no longer an issue

Thanks
Reply With Quote
  #19  
Old 06-13-2010, 11:01 AM
Lauren Lauren is offline
LiteSpeed Staff
 
Join Date: Jul 2003
Location: New Jersey, USA
Posts: 99
All platform builds have been updated.

If you are unable to upgrade at this moment, please add mod_security rules to block this exploit suggested by khunj on webhostingtalk

Quote:
Just add this to 'Request Filter' at the server level:

Name : NULLBYTE
Action: deny,log
Eabled: yes
Rules Definition: SecRule REQUEST_URI "\x00"

Restart LS.
4.1RC build will be updated later.
Reply With Quote
  #20  
Old 06-13-2010, 12:16 PM
AndrewT AndrewT is offline
Senior Member
 
Join Date: Jan 2010
Posts: 66
Upgraded all servers and it seems to resolve the issue. Though the web console now seems to think 4.0.13 is the latest and should be installed.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 10:48 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.