• Security problems - worm

  • OpenKM has many interesting features, but requires some configuration process to show its full potential.
OpenKM has many interesting features, but requires some configuration process to show its full potential.
Forum rules: Please, before asking something see the documentation wiki or use the search feature of the forum. And remember we don't have a crystal ball or mental readers, so if you post about an issue tell us which OpenKM are you using and also the browser and operating system version. For more info read How to Report Bugs Effectively.
 #13154  by garret
 
Hello,

my OpenKM installation was attacked by a worm (perl script called fly.pl). The JMX console etc. were secured.
After some google research I found out that the worm could enter the server because of a JBoss security hole and that it has been fixed with newer JBoss versions.
So my question is: what can I do to avoid the possibiltiy of being attacked again. Is there (for example) any way to install OpenKM with a newer version of JBoss?

Thanks in advance
garret
 #13164  by jllort
 
The way to solve it, is not exposing your jboss port 8080 directly to internet. If you want to expose it, use apache proxy configuration to mapping port 8080 to apache 80 port across proxy configuration.

In newsletter will send next week will explain this jboss problem.
 #13182  by jllort
 
Today we've starting sending newsletter, then will publish in forum too.
 #13189  by pavila
 
There is a JBoss vulnerability which can be used to write files in the filesystem (https://issues.jboss.org/browse/JBAS-3861). To protect you JBoss installation don't expose JBoss directly to the Internet. Use Apache to handle petitions and forward to the JBoss instance. More info about this at http://wiki.openkm.com/index.php/Apache.
 #13238  by olexandr
 
Hi!
Thank you for the documentation - how to configure apache.
I've got zmeu.war with console password-protected.

How to subscribe to newsletter?
 #13245  by jllort
 
Go to our website http://www.openkm.com press right top download icon and fill the form to subscribe newsletter. Your question make to think to me that I should put a specific menu option for it.

About Us

OpenKM is part of the management software. A management software is a program that facilitates the accomplishment of administrative tasks. OpenKM is a document management system that allows you to manage business content and workflow in a more efficient way. Document managers guarantee data protection by establishing information security for business content.