xampp 7.3 script injection (XSS)

Problems with the Windows version of XAMPP, questions, comments, and anything related.

xampp 7.3 script injection (XSS)

Postby markzil » 30. September 2019 16:33

Good morning,
After months of warnings to upgrade our PHP version to 7.*.* we upgraded to 7.3.9. Sadly, a week after I had it up and running, we were hacked, our databases removed and held for ransom. We are running Joomla! 3.8.4 and WordPress 5.2.3 on a Windows 2012 r2 server. I thought you might like to know and perhaps you can help me with a fix. We were able to restore the site with a back-up and we shut it down to the outside world, but I have international students who need access to the content.
Thank you,
Mark
markzil
 
Posts: 1
Joined: 30. September 2019 16:22
XAMPP version: 7.3.9
Operating System: Windows 2012 r2

Re: xampp 7.3 script injection (XSS)

Postby Altrea » 30. September 2019 18:26

Hi Mark,

I cannot emphasise strongly enough that XAMPP is not meant for public accessible servers.
It is listed in the stickies and several dozens of posts here at this forum
it is listed in every XAMPP installation readme_en.txt
it is listed on the official Apachefriends FAQ

Maybe you have learned a lesson now.

best wishes,
Altrea
We don't provide any support via personal channels like PM, email, Skype, TeamViewer!

It's like porn for programmers 8)
User avatar
Altrea
AF Moderator
 
Posts: 9861
Joined: 17. August 2009 13:05
XAMPP version: several
Operating System: Windows 10 Pro x64

Re: xampp 7.3 script injection (XSS)

Postby Nobbie » 30. September 2019 21:26

markzil wrote:Good morning,
After months of warnings to upgrade our PHP version to 7.*.* we upgraded to 7.3.9. Sadly, a week after I had it up and running, we were hacked, our databases removed and held for ransom.


Of course. Not very surprising. From http://localhost/dashboard

XAMPP is meant only for development purposes. It has certain configuration settings that make it easy to develop locally but that are insecure if you want to have your installation accessible to others.


What part of it is incomprehensible?
Nobbie
 
Posts: 11221
Joined: 09. March 2008 13:04


Return to XAMPP for Windows

Who is online

Users browsing this forum: No registered users and 46 guests