Results 1 to 6 of 6

Thread: Sugar vulnerabilities??

  1. #1
    Syfa is offline Member
    Join Date
    Jul 2010
    Posts
    6

    Default Sugar vulnerabilities??

    Hi Peops,

    New on here but have used the forum for pointers right from the word go - so thank you!

    I have had Sugar installed on my Host now for about 3 months - we are trialling it in our company and are considering buying aspects etc.... I am quite taken with the functionality and the fact it makes it crystal clear to monitor my co-workers etc.

    Since I have installed it I have been hit twice by Virii ON my host, Prior to this I have been with the same host with no other changes for about 5 years now!

    To get two hits in less than 2 months has really got me worried now and I wondered if it could be a patch or known vulnerability I have missed off? One was a basic redirect - but the second was massive and it rewrote EVERY php file in my Home Dir with encrypted coding - offering all my customers spyware.

    as you can imagine I had to take my sites down immediately - it is repaired but how did it happen? I would be really grateful if anyone has come across this before or has any advice!

    Many thanks

  2. #2
    Syfa is offline Member
    Join Date
    Jul 2010
    Posts
    6

    Default Re: Sugar vulnerabilities??

    oops - it is Sugar CE-5.5.1

  3. #3
    Syfa is offline Member
    Join Date
    Jul 2010
    Posts
    6

    Unhappy Re: Sugar vulnerabilities??

    Is my question that bad

  4. #4
    REByers is offline Sugar Community Member
    Join Date
    Oct 2007
    Location
    North West England
    Posts
    182

    Default Re: Sugar vulnerabilities??

    From my experience Sugar is no more, or less vulnerable than any other PHP web app.

    It's more down to your securing of the server, firewall and AV setup than anything else.

    If you don't secure your boxes then they would be wide open, no matter what site you have running.

  5. #5
    joshh is offline Member
    Join Date
    Apr 2010
    Posts
    12

    Default Re: Sugar vulnerabilities??

    If someone gets your sugar admin password then they can upload and run any malicious php code that they want using module loader. If you don't have a strong password for the admin user you leave a pretty big opening.

  6. #6
    Syfa is offline Member
    Join Date
    Jul 2010
    Posts
    6

    Default Re: Sugar vulnerabilities??

    Thank you guys - I will double check and change regardless - I have been hit AGAIN now EVERY PHP file on the site has been hit

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Secunia is reporting Sugar vulnerabilities
    By salesagility in forum General Discussion
    Replies: 3
    Last Post: 2009-11-29, 04:56 AM
  2. Warning: JotPad Vulnerabilities
    By chad.hutchins in forum Developer Help
    Replies: 3
    Last Post: 2008-10-27, 06:37 PM
  3. Replies: 8
    Last Post: 2008-07-12, 06:13 PM
  4. more information on vulnerabilities?
    By niels in forum Help
    Replies: 1
    Last Post: 2006-09-18, 10:53 AM
  5. Replies: 0
    Last Post: 2004-12-28, 10:15 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •