LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > litespeed hacked?

Reply
 
Thread Tools Display Modes
  #31  
Old 06-16-2010, 07:32 AM
robfrew robfrew is offline
Senior Member
 
Join Date: Dec 2007
Location: Salt Lake City UT
Posts: 151
It looks like I cannot get into any secure (https) areas of any website running the patched RC2. That is why I cannot get into the control panel because it resides on a secure setup. I had to load the original RC2 to get my secure sites to work again.
Reply With Quote
  #32  
Old 06-16-2010, 09:22 PM
robfrew robfrew is offline
Senior Member
 
Join Date: Dec 2007
Location: Salt Lake City UT
Posts: 151
Any updates or fixes for this yet?
Reply With Quote
  #33  
Old 06-17-2010, 06:33 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Have updated RC2 to address the https issue.
which edition are you using? i386 or x86_64? want to address the issue with 4.1RC3
Reply With Quote
  #34  
Old 06-17-2010, 06:42 PM
robfrew robfrew is offline
Senior Member
 
Join Date: Dec 2007
Location: Salt Lake City UT
Posts: 151
Quote:
Originally Posted by mistwang View Post
Have updated RC2 to address the https issue.
which edition are you using? i386 or x86_64? want to address the issue with 4.1RC3
We are using x86_64.
Reply With Quote
  #35  
Old 06-24-2010, 12:02 PM
robfrew robfrew is offline
Senior Member
 
Join Date: Dec 2007
Location: Salt Lake City UT
Posts: 151
Quote:
Originally Posted by mistwang View Post
Have updated RC2 to address the https issue.
which edition are you using? i386 or x86_64? want to address the issue with 4.1RC3
Looking forward to RC3.
Reply With Quote
  #36  
Old 07-20-2010, 04:20 PM
luky luky is offline
New Member
 
Join Date: Oct 2008
Posts: 2
This filter do not work for 4.0.10
Quote:
GET /index.php
2010-07-21 01:38:07.676 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Find context with URI: [/], location: [/home/www/domains/MY-DOMAIN.com/html/]
2010-07-21 01:38:07.676 [DEBUG] [HTAccess] Updating configuration file [/home/www/domains/MY-DOMAIN.com/html/.htaccess]
2010-07-21 01:38:07.676 [INFO] [HTAccess] Updating configuration from [/home/www/domains/MY-DOMAIN.com/html/.htaccess]
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Find .htaccess context with URI: [/], location: [/home/www/domains/MY-DOMAIN.com/html/]
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] processContextPath() return 0
2010-07-21 01:38:07.677 [INFO] [184.193.59.46:59568-0#MY-DOMAIN.com] no request variables, skip ruleset: XSS attack
2010-07-21 01:38:07.677 [INFO] [184.193.59.46:59568-0#MY-DOMAIN.com] no request variables, skip ruleset: SQL Injection attack
2010-07-21 01:38:07.677 [INFO] [184.193.59.46:59568-0#MY-DOMAIN.com] [SECURITY] match [REQUEST_URI] against pattern [\x00], result: 1
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] readyCacheData() return 0
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Written to client: 453
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] m_pHandler->onWrite() return 0
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] HttpConnection::flush()!
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] HttpConnection::nextRequest()!
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Non-KeepAlive, CLOSING!
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] processNewReq() return 0.
2010-07-21 01:38:07.677 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Shutting down out-bound socket ...
2010-07-21 01:38:07.792 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] HttpIOLink::handleEvents() events=17!
2010-07-21 01:38:07.792 [DEBUG] [184.193.59.46:59568-0#MY-DOMAIN.com] Close socket ...
screenshot from admin panel Request Filter
grab.by/grabs/6082dddb30bf07cfe7fb187fe2e721de.png
Reply With Quote
  #37  
Old 07-20-2010, 07:35 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,226
best to upgrade to 4.0.15
Reply With Quote
  #38  
Old 07-20-2010, 07:48 PM
luky luky is offline
New Member
 
Join Date: Oct 2008
Posts: 2
I know, but it has turned out to force to work for me
Quote:
Action:log,deny,status:403
Reply With Quote
  #39  
Old 07-21-2010, 01:56 AM
J.T. J.T. is offline
Member
 
Join Date: Apr 2010
Posts: 47
Couple of questions regarding this.

1. How can we check whether the server may have already been compromised before upgrading or applying the mod sec rule?

2. If we don't log in to the LSWS admin UI we wouldn't know there's an update. Even if we did, it doesn't exactly highlight the update as urgent/crucial. Some updates recently were just for some control panel integration so I waited on those. It would be really handy if there was an RSS feed to monitor this type of news (without having to subscribe to every forum thread, then filter them). I don't see a feed on the news items, which would have been perfect. Can you please consider this point and let us know how best to be fed updates?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:30 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.