Is Muse safe from hacking?

Dear Muse support team,
I am creating a website using Muse, and use our own company server.
Recently, we received an alert email from cPanel. Below is the original message we've got.
Note: If this is the first time you received this mail, it contains the history for the entire month so far.
Below are the recently upload scripts that contain code to send email.  You may wish to inspect them to ensure they are not sending out SPAM.
/home/anmadmin/public_html/myparentalcontrols/scripts/form_check.php:108:                     {
/home/anmadmin/public_html/myparentalcontrols/scripts/form_check.php:109:                               $sent = mail("[email protected]", "Hi", "test message", "From: [email protected]");
/home/anmadmin/public_html/myparentalcontrols/scripts/form_check.php:110:                               if($sent)
Forfunately, we found out the message isn't really serious issue and we can simply ignore. However, my boss suspects we got that message because of some of Muse files and he's worried about security concerns when we use Muse.
How can I figure out which file could make this message sent?
Also, I'm wondering is there any Muse code refers to outside javascript or add php or javascript to our site withought a thorough security vetting?
Look forward to hearing from you.
Sincerely,
Thank you.

That is not entirely true. Mues does generate PHP files when you use the formular widget.
Furthermore, it generates a file named form_check.php which is apparently meant for checking the server-configuration. The file even attempts to send testmails to the adresses seen in the OP.
Sadly, this file is completely unsecure and can be called by anyone who knows the name.
Hence this file can very easily lead to errors and spam-warnings from your provider.
Until Adobe decides to fix this or to atleast warn users about the existance of that file, I suggest you add the following lines  to a .htacces file on your server:
<FilesMatch "form_check.php$">
deny from all
</FilesMatch>

Similar Messages

  • Spyware for iPhone... Does it exist.. Is an I phone safe from hacking

    Spyware for iPhone... Does it exist.. Is an I phone safe from hacking

    Simple question, complicated answer. If the phone is not jailbroken there is no known spyware that can be installed remotely. However, any application can gain access to your contacts, calendar, email and location. This is either a feature if you are aware of it and want it or a risk if you don't. For example, apps like foursquare will report your current location to your "friends". But there was recently an app that would use Foursquare to report the location of any women near you (it has been withdrawn after some bad publicity). Some applications will make copies of your contact list and send to their servers. They are supposed to ask before doing so, but Apple does not enforce this rule. Why would they do this? Because knowing who your contacts are, and their interests from the Facebook sites, they can learn more about you and how to market to you. They might also reach out to your contacts to market to them directly.
    With hundreds of thousands of apps available, some probably do things that they shouldn't. So be careful in the apps you choose.

  • I am using i padmini with retina display. i was curious to know if the pdf files saved on adobe reader app are safe from any hacking

    I am using i padmini with retina display. i was curious to know if the pdf files saved on adobe reader app are safe from any hacking

    If they are saved on your iPad, they are as safe as anything else.
    Barry

  • I have downloaded Firefox 4 and when I open Firefox again I get the message that my version is not safe from online attacks, so why?

    I opened Firefox and got the message that I needed to download 4 because my version was not safe from attacks. I downloaded 4 and then I quit Firefox and reopened it, and got the same message as before. I am probably doing something incorrectly, but I have no idea what that could be.
    Thanks.

    The Firefox 3.5.x branch has reached end-of-life and is no longer maintained.<br />
    You will no longer receive security updates.<br />
    You can update Firefox via "Help > Check for Updates" or download and install the latest Firefox 3.6.x or 4.0.x version.<br />
    * Firefox 4.0.x: http://www.mozilla.com/en-US/firefox/all.html
    * Firefox 3.6.x: http://www.mozilla.com/en-US/firefox/all-older.html

  • Can you let me know if its possible to import a muse site from Business catalyst in to Dreamweaver?

    Can you let me know if its possible to import a muse site from Business catalyst in to Dreamweaver? I have published a site using Muse to Business catalyst but would like to use FTP in dreamweaver to administer and edit.

    I think you could but you wouldn't like what you see in Design View.   Why do you want to do this?
    Nancy O.

  • How to create MUSE file from existing MUSE site?

    Hi-
    A customer has a site that was created with MUSE and she wants some edits made to it.
    I have installed MUSE and can access the server via FTP. I've downloaded the site's html files and assets, but these are useless in MUSE.
    How do I create or get the whole site's MUSE file from the server so I can make the edits and put back on her server?
    Thanks for any guidance here.

    Hello,
    You would need the .muse file (source file of website). And you can get it only from the person who created it.
    It must b saved on their local machine. This file  is not uploaded on the  server via FTP. And you cannot use the .html and other output files as the changes need to be made in that .muse file.
    Regards,
    Sachin

  • Is lion still safe from Zeus malware? I was an idiot and was fooled by a fake LinkedIn email

    Is lion os still safe from Zeus malware? I was an idiot an fell for a fake LinkedIn message. Not sure if anything happened. Also, is the iPhone safe as well?

    Back in 2006 I responded to a promotion from Apple enabling me to buy Final Cut Studio at a huge discount, if I would send them my Final Cut Pro serial #. I did that
    I took advantage of the same "crossgrade" offer. If I recall correctly, they didn't ask for you to send them your serial number. They required you to send your old FCP install disc. Here's the instructions from the PDF order form for the offer:
    Instructions
    1. Fill out this order form and enclose it with
    payment of US$199 plus applicable sales tax
    and your original Final Cut Pro 4 or Final Cut
    Pro HD Install DVD for each Final Cut Studio
    Upgrade Kit ordered.
    Apple recommends that you make
    photocopies of the completed order form
    and the face of the Final Cut Pro 4 or Final
    Cut Pro HD Install DVD for your records.
    2. Mail the completed order form, payment, and
    the original Final Cut Pro 4 or Final Cut Pro HD
    Install DVD to:
    Apple
    My point is that IF you sent in the old install disc, you may still have the old serial number. It was originally printed on two labels and was affixed to the front of the booklet titled "Installing Your Software."
    My upgrade was from FCP 4.5 ... but you may have upgraded from a different version. It may be worth a look to see if you can find it.
    -DH

  • Does self service personalization safe from the patch?

    We're testing Self Registration in iReceivables. Our Finance wants LOV on the job title field. I believe this can be done in personalization. My question is does personalization safe from the patches? I know form personalization is safe but I'm not sure about self service personalization.

    user613835 wrote:
    We're testing Self Registration in iReceivables. Our Finance wants LOV on the job title field. I believe this can be done in personalization. My question is does personalization safe from the patches? I know form personalization is safe but I'm not sure about self service personalization.Product upgrades and patching only affect the base metadata definition so that customer personalizations are preserved and continue to function properly.
    Oracle Application Framework Developer's Guide Release 12.1.3 [ID 1107973.1]
    Oracle Application Framework Developer's Guide Release 12.1.2 [ID 972774.1]
    Thanks,
    Hussein

  • When downloading adobe muse trial from adobe application manager

    adobe muse trial from adobe application manager im getiting error, 12152

    Some users have reported issues with Internet Explorer 9 although it does not appear to be consistent.  It is likely due to the security settings, install add-ons, or plug-ins which are causing the download button to not be available.

  • How do I block an iPad app from hacking my Time Capsule WiFi?

    I have a 1st gen Time Capsule. I use it for my Wi-Fi signal in the house. A kid with an iPad has an app that keeps hacking my Wi-Fi password every time I change it. Is there a way for me to block that app from hacking my Wi-Fi? If so, how?
    Again, it is a 1st gen Time Capsule, and my computer is a mid-2007 iMac. I use WPA2 Personal for my wireless security. My password has letters, numbers, and special characters, and is not easily remembered. I had to write it down in case I need to enter it on a new wireless device, yet this kid just hacked right in.
    Any and all helpful info will obviously be greatly appreciated.
    Thanks

    A couple of things.
    The advice on the passwords above is good. FING recomendation was great as well - It's a great APP.
    https://itunes.apple.com/us/app/fing-network-scanner/id430921107?mt=8
    However, there is another possibility - Does he know your Time Capsule's Admin password? With that he can use an app to quickly get your WIFI password and get on the network. Have you tried changing the admin password.
    If you've installed this app: https://itunes.apple.com/us/app/airport-utility/id427276530?mt=8
    It will ask you for an admin password to access the Time Capsule. If you're using the same password each time for admin access then he can get access to the admin rights and there are ways of getting the password from there, quite easily.
    P.S. Change the password on your iMAC in case he has accessed it and installed a key logger. (There used to be physical keyloggers that would be discreetly put inline between the keyboard and the computer but I don't think there is one for Macs and with the advent of Bluetooth keyboards it's a moot point)
    <Link Edited by Host>

  • Is mac really safe from viruses

    Is mac really safe from viruses....

    There are no know viruses that can infect your Mac OS system at the present. You can still receive and sent Windows files that are infected to Windows users. (This can be either good or bad )
    Still any OS, including Mac, is open to Trojans which are malicious code that is disguised as something desirable. The latest being MacDefender, which Snow Leopard looks for and helps remove. http://support.apple.com/kb/HT4651

  • Is Firefox 36.0.1 safe from the Freak bug?

    I've heard, for the most part, that Firefox 36.0.1 is safe from the Freak bug, but a few reports indicate this might not be so. Is there any definitive word on the question? If Firefox isn't safe, does anyone know about the development of a patch?

    The main basic steps are
    # Keep everything up to date
    # Use Anti-Virus software
    # Try to be aware of risks and good practice.
    Have a look at
    * https://support.mozilla.org/products/firefox/privacy-and-security
    ** [[How to stay safe on the web]]

  • Are Laptops inherently Safe from Power Spikes and Failures?

    Are laptops like the iBook or MacBook series inherently safe from power spikes and short power failures due to the fact that they essentially are running on battery power all the time anyway? Should one use a UPS for a laptop?
    I have my iBook connected through a surge protector, but it is not connected to a UPS as well. Should it be? The reason I ask is that today, there was one of these split second power failures. I was not at the computer at the time, but noticed that the printer recycled. When I went to my iBook it was dead. I couldn't start it by pushing on the start button either with the power cord plugged or unplugged. I thought it had gotten zapped some how. But how?
    Just for grins, I removed the battery and plugged in the power cord. It started up fine. I powered down, place the battery back in and it started fine on the battery as well. What do you suppose was going on here?
    -Bill

    Bill,
    No, it isn't. You can get power spikes through the AC power cord, the modem, the ethernet port, or any peripheral connected to the computer. A power conditioning UPS is your best bet for protecting it. Make sure that all other connections are also routed through the UPS, too.
    It's likely that what happened was that the clamping voltage for the surge protector was too high/too slow to completely prevent a surge into your laptop - either on power down or on main power restoration. It wasn't enough to fry it, but was enough to trigger an overload. Removing the battery allowed it to reset and operate normally.
    Since I live in Lightning Central every monsoon season, I can tell you from experience that it is far less expensive to replace a burnt out power-conditioning UPS (or UPS batteries) every few years than it is to replace a boatload of cheap surge protectors or non power-conditioning UPSes and attached hardware.
    -Wayne

  • My phone was hacked at a wifi hotspot, and my email address logged in the mail centre was compromised.. Could they have installed a keylogger on my phone? Is there anything I have to do to my phone to ensure its safe from this particular attack?

    I changed all my passwords, but I'm just wondering if that's all I have to do.. Is there any extra measures you would take? Could they have installed malware on my phone? I will never connect to a wifi hotspot ever again. I'll just use 3G!

    I have this really old email account that I haven't used properly in years, it was automatically set to log in the mail centre of this old iPhone I barely use, and was only using because my other phones battery had died, and I was at the park, bored, so I got the old phone out of my bag, I use it as an emergency phone for when my battery dies, but anyway, I logged into the hot spot, then a few days later my old email account had sent out a mass email saying "I am stranded in Thailand, please send money to this account" to my entire contact list, my sister sent me a text notifying me, and I quickly logged on and it said "looks like someone else is using your account" so I got texted a code, entered the code and regained access to my hotmail account, checked the sent folder and there were tons of sent messages..haven't used this account for many months before that, and I never log into public hotspots usually, it was a one off thing I did from that old phone because I thought I had no email account logged in, or any personal information, since I hadn't used it in ages, but I was wrong, as I learnt afterwards! So I'm absolutely certain, without a doubt, that it occurred at the hot spot. I looked it up online and apparently it is quite common, so I'm just wanting to make sure they can't still access my data.

  • How do I stop someone from hacking my iPhone?

    Hello all
    This question concerns hacking of an iPhone and possible installation of a keystroke logger on my MacBook Air.
    A month or so ago my iPhone 5c was hacked. Text messages were sent without any action on my part, apps on my iPhone were deleted and new ones were downloaded, mainly games. When I tried to stop them downloading, I got messages asking if I wanted to delete apps I had previously downloaded. The hackers had got my AppleID somehow, and had changed the language on the AppleID site to Korean!
    It took me some time, but with the help of Apple Care I managed to restore the iPhone, or so I thought.
    I was more recently the victim of a "spamming attack" on my MacBook Air where e-mails were sent from my computer by a spammer. I changed the password on my e-mail account. Since then on 3 occasions I have observed weird mouse behaviour when using Internet: twice it was impossible to move on a web page, I became stuck at the bottom of a page and had to reboot; another time a video I was watching went into a kind of slow motion, starting and stopping again several times a second. So it seems like I have some sort of malware on my Mac. Perhaps I should mention I am running Parallels software on my MacBook Air.
    Now I have the problem with my iPhone again; whenever I have the "Localisation service" option on, text messages are entered on my phone, although none have been sent yet.
    When I went on the AppleID website yesterday, my birthdate had been changed, so apparently they have got my AppleID password again. I changed the password yesterday.
    Could they get the password through iCloud? or a keystroke logger on my computer? I read here that a keystroke logger can be installed by a fake JavaScript (or Java) installation window, and I remember clicking on such a window a few months ago. That would explain the spamming attack too. If that is the case do I have to "wipe" the whole HD, or just reinstall the OS?
    Thanks in advance for any help.

    It sounds as if your Apple ID was hacked. Your iPhone would have to have been jailbroken in order to have been hacked. Most likely, the hackers would have also have had to have had physical access to your phone. To protect the phone itself, don't jailbreak it and put a password on it. It sounds as if you did the right thing getting the Apple ID sorted. Make sure you use a strong password from now on.
    Regargind your computer, again, it sounds as if your email was hacked. Sending spam that appears to have come from your email address wouldn't even have needed that. You could have malware in your Windows partition, I supposed. It is unlikely, though not absolutely impossible that you have malware running under the Mac OS.
    You probably want to look into two-factor authentication with your Apple ID. I'm not an expert on malware on computers (as I have a Mac and it's not really a major issue) but, I think that wiping the Parallels partition and reinstalling would get rid of any possible Windows issues.
    Best of luck.

Maybe you are looking for

  • MASS CREATION of new inforecords and loading it in mass

    Iam new to SAP MM .can anyone please let me know 1. what MASS CREATION OF NEW INFO RECORDS MEANS. Is it somethnig other than creating the info record using the TCODE ME11? 2. what LOAD INFO RECORD IN MASS means?

  • How to delete infoobject by transport request?

    Hi experts, I want to delete infoobject from productive system by transport request without deleting this infoobject from development system. Is it possible? How can I do this? Thanks!

  • Forms 10g compile : syntax error near unexpected token `in

    Hi, I am writing a code to compile FORMS 10g(10.1.2.0.2) in HP_UX one by one. this is the code---frm10g.sh *#!/bin/ksh* *# . ~oracle/forms/server/default.env* *# . sid icache* TERM=vt220 *if [ $# != 2 ]* then echo Usage : $0 module_name module_type e

  • Best way to manage login page without Tabs in Tabbedapplication

    HI fellow developers! I'm encountering a problem while building my first Tablet application. I'm using Flex that communicates with PHP, that's no problem at all. I've created a testapp to test my services and everything works fine. Now, i've started

  • AppleMobileDeviceHelper Error in Windows version of iTunes 7.6

    Hello, I am getting a AppleMobileDeviceHelper error when I open the new iTunes. I never had it with the previous version. I have a newer iPod nano and it seems to work fine. The error message keeps coming up on the screen, no matter what I seem to do