Results 1 to 6 of 6

Thread: OpenX Serving Malware?

  1. #1
    Moderator Bec's Avatar
    Join Date
    Nov 2003
    Location
    Ohio
    Posts
    8,419

    OpenX Serving Malware?

    Some users of OpenX are still reeling and recovering from hacker attacks just last Sept. 2010, when an OpenX banner page hack placed a malicious JavaScript or Iframe into the banner page produced by an OpenX ad server.

    This was often accomplished with a plugin and in some other cases the malicious code itself was injected into the OpenX database. Hackers have inserted backdoor scripts, which allow the hacker to obtain remote access to the hacked ad server. In some cases hackers added additional user accounts to the ad server. This was able to infect ad servers running up to version 2.8.6 (check what version you are currently running). OpenX has announced that they patched an undisclosed vulnerability in version 2.8.7, they also have a post with advice on cleaning up after a hack that took advantage of this. A previous hack infected ad servers last December, 2009 and was patched in version 2.8.3

    And now from Sucuri.net, a blog that does research and tracks website hacking and blacklisting, came this post on Jan. 7th, 2011:

    We are tracking a few sites that are currently blacklisted and showing a warning from Google that openx.org (home of a popular open source ad server) is the site responsible for the infection: 2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including openx.org/.

    By looking at the diagnostic page for openx.org itself, it shows:Has this site acted as an intermediary resulting in further distribution of malware?

    Over the past 90 days, openx.org appeared to function as an intermediary for the infection of 82 site(s) including solovenezolanas.com/, thelocal.de/, drtuber.com/.

    We are still tracking to see which ads are causing the issue, or if the openx servers themselves are compromised. If you include the tracking code from openx.org, we recommend that you check to see if there isn’t any malicious code being pushed to your users.
    I was considering using this script, but am a bit leary of doing so now. Even being "hardened" with all the security Wordpress script upgrades, this one worries me. Anyone here have any experience with dealing with the OpenX issues?


  2. #2
    virgin by request ;) HunkyLuke's Avatar
    Join Date
    Mar 2008
    Posts
    3,194
    I have heard of issues like this as well, I also read that protecting the admin directory with an .htaccess / .htpasswd stops these types of attacks so that is what I did....but, yeah, its still a bit of a worry!!!
    Luke H.
    Marketing Director
    Zbuckz.com, Jbuckz.com, Dickbank.com, Glamourbuckz.com


  3. #3
    Am I Bitter?...Absolutely nicedreams's Avatar
    Join Date
    Apr 2004
    Location
    Washington DC Metro
    Posts
    572
    We were using it until one of our sites got blocked by google because it got malware from openx. It took 2 months to get the compromise message off google.

    Jimmy

    Gay Amateur Paysites / Solo Twink Paysite
    Nice Dreams Cash
    http://www.nicedreamscash.com


  4. #4
    virgin by request ;) HunkyLuke's Avatar
    Join Date
    Mar 2008
    Posts
    3,194
    Wow, 2 months? thats horrible! What did you replace it with?
    Luke H.
    Marketing Director
    Zbuckz.com, Jbuckz.com, Dickbank.com, Glamourbuckz.com


  5. #5
    Am I Bitter?...Absolutely nicedreams's Avatar
    Join Date
    Apr 2004
    Location
    Washington DC Metro
    Posts
    572
    We just wrote a script that randomly selects a banner from a php file.

    Jimmy

    Gay Amateur Paysites / Solo Twink Paysite
    Nice Dreams Cash
    http://www.nicedreamscash.com


  6. #6
    Moderator Bec's Avatar
    Join Date
    Nov 2003
    Location
    Ohio
    Posts
    8,419
    Quote Originally Posted by nicedreams View Post
    We just wrote a script that randomly selects a banner from a php file.

    Jimmy
    Well hells bells, I could of given you one of those! :cheer:


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •