Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Google Searching - "powered by getsimple"
Author Message
RobA Offline
Senior Member

Posts: 272
Joined: Oct 2010
2012-07-17 01:26:36
Google Searching - "powered by getsimple"
Not sure if this is the appropriate place to post this - consider it a small warning.

I've noticed a number of hits on my website coming from google, where the search term is "powered by getsimple"

This is the default tag on (most?) themes.

I've since removed this line from my site, since the only two reasons I can imagine someone searching for this phrase is to audit for popularity of the CMS (which wouldn't need to click through to my site) or to locate GS sites in order to target a vulnerability.

Just a warning to you all to keep an eye on any suspicious activities, especially if you see that phrase in your keyword referrals.

-Rob A>

Try the SimpleCache plugin!
Try the Client Files plugin!
Try the External Commenting plugin!
Find all posts by this user Quote this message in a reply
sal Offline
Member

Posts: 149
Joined: Jan 2010
2012-07-17 01:42:22
Google Searching - "powered by getsimple"
Agreed, I know of at least one plugin with a nasty vulnerability that needs to be patched.

Thanks for the free web-hosting Capnix!
Find all posts by this user Quote this message in a reply
hameau Offline
Member

Posts: 201
Joined: Mar 2011
2012-07-17 05:29:43
Google Searching - "powered by getsimple"
I first noticed these hits some time ago. I was sure I had posted about it, but perhaps not. It was about the time that an alleged vulnerability was posted to forum (subsequently discredited – I can't find that, either).

While I do have the footer link to GS, there's no way I would expose the GS version number on the admin login page, which is there by default. I have been the victim of a site hacking (with a different CMS), when a vulnerability in FCKeditor was targeted, based on the CMS version number being advertised. A similar Google search term was apparent in that case, too.

--
Nick.
Find all posts by this user Quote this message in a reply
n00dles101 Offline
Administrator

Posts: 981
Joined: Aug 2009
2012-07-17 06:21:39
Google Searching - "powered by getsimple"
I sent a message last month to the 2 vulnerable plugins authors..

Agree we should probably remove the version number from the admin panel login page as its only leaving us open to chancers !!

I'll put it on the issue tracker for the next release.

My Github Repos: Github
Website: DigiMute
Visit this user's website Find all posts by this user Quote this message in a reply
Connie Offline
Super Moderator

Posts: 2,719
Joined: Feb 2011
2012-07-17 15:53:07
Google Searching - "powered by getsimple"
n00dles101 wrote:I sent a message last month to the 2 vulnerable plugins authors..

did they react?
If not, maybe these plugins should be removed from the repository?

|--
Die deutsche GetSimple-Webseite: http://www.Get-Simple.de = the german Get-Simple-Website!
Das deutschsprachige GetSimple-(Unter-)Forum: http://get-simple.info/forums/forumdisplay.php?fid=18
Find all posts by this user Quote this message in a reply
Post Reply 




User(s) browsing this thread: 1 Guest(s)

Contact Us | GetSimple | Return to Top | Return to Content | Lite (Archive) Mode | RSS Syndication
Generate Leads from Documents vCard Hosting