Backdoor found in OpenX ad platform

Powered by SC Magazine
 

Package compromised since 2012 permits remote hijack.

A backdoor has existed for up to nine months in an platform offered OpenX , the self-described global leader of digital advertising which counts the New York Post, Coca Cola, Bloomberg and EA among its customers.

The backdoor was contained within the official OpenX package and recently removed.

It meant according to Sucuri researcher Daniel Cid that anyone who downloaded the product could have provided attackers "full access" to their web sites. 

"That’s how serious it is,"  Cid said.

StopMalvertising researcher Kimberly obtained a copy of the compromised file dated September 2012.

She said the backdoor, first reported by Heise Security (German), exists in the zip, tgz and bz2 archives of the software. 

"After examining openXVideoAds.zip, I was able to locate the PHP code in flowplayer-3.1.1.min.js, a file located in the plugins\deliveryLog\vastServeVideoPlayer\flowplayer\3.1.1 folder," she said.

"Server administrators can find out if they are running the OpenX version that contains the backdoor by searching for PHP tags inside .js files."

Users have warned administrators should be vigilant regarding potentially vulnerable installations of OpenX that their organisations have since disused.

OpenX have been contacted for comment and said they were aware of the reports but was not yet prepared to make a statement.

More to come.

Copyright © SC Magazine, Australia


Backdoor found in OpenX ad platform
 
 
 
Top Stories
Myer CIO named retailer's new chief executive
Richard Umbers to lead data-driven retail strategy.
 
Empty terminals and mountains of data
Qantas CIO Luc Hennekens says no-one is safe from digital disruption.
 
BoQ takes $10m hit on Salesforce CRM
Regulatory hurdles end cloud pilot.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  17%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 4059

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1390

Vote