{"id":2210,"date":"2014-11-13T15:49:00","date_gmt":"2014-11-13T22:49:00","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2210"},"modified":"2014-11-13T15:49:00","modified_gmt":"2014-11-13T22:49:00","slug":"godaddy-distributing-software-with-known-security-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/11\/13\/godaddy-distributing-software-with-known-security-vulnerabilities\/","title":{"rendered":"GoDaddy Distributing Software With Known Security Vulnerabilities"},"content":{"rendered":"<p>Oftentimes when a website is hacked the\u00a0web host will blame the hack on outdated software running on the website. From our experience they often do this without any evidence to back that up and in some cases they obviously haven&#8217;t even checked if the website is running outdated software since the website in question was using up to date software at the time of the hack. Based on that you would think that web hosts would be very careful when distributing software to their clients that they make sure that it is up to date, but as we keep seeing that isn&#8217;t the case. The latest example\u00a0this came up while we were looking into <a title=\"GoDaddy\u2019s Bad Response to the Drupal 7 Vulnerability\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/11\/12\/godaddys-bad-response-to-the-drupal-7-vulnerability\/\">GoDaddy&#8217;s bad response to the Drupal 7 vulnerability<\/a>. We noticed in their Hosting Connection, which they say has been used to install 6.9 million apps, that they were still installing Drupal 7.32:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/Drupal.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2212\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-drupal.png\" alt=\"GoDaddy's Hosting Connectin is installing Drupal 7.32\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-drupal.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-drupal-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>Drupal 7.33 was <a href=\"https:\/\/www.drupal.org\/drupal-7.33\">released<\/a> last Friday and includes &#8220;numerous bug fixes&#8221;. Since the new version didn&#8217;t include any security fixes it wasn&#8217;t a huge issue that they hadn&#8217;t updated\u00a0the version they installed yet. But then we started looking at the version of other software they were offering and things got much worse.<\/p>\n<p>They are still installing Joomla 2.5.14:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/Joomla.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2216\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-joomla.png\" alt=\"GoDaddy's Hosting Connectin is installing Joomla 2.5.14\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-joomla.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-joomla-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>That version is now a year out of date, the next version was released on November 6, 2013, and GoDaddy hasn&#8217;t updated their Joomla version despite there having been\u00a0four\u00a0subsequent releases with security fixes (<a href=\"http:\/\/www.joomla.org\/announcements\/release-news\/5517-joomla-2-5-15-released.html\">2.5.1.5<\/a>, <a href=\"http:\/\/www.joomla.org\/announcements\/release-news\/5537-joomla-2-5-19-released.html\">2.5.19<\/a>, <a href=\"http:\/\/www.joomla.org\/announcements\/release-news\/5563-joomla-2-5-25-released.html\">2.5.25<\/a>, and <a href=\"http:\/\/www.joomla.org\/announcements\/release-news\/5566-joomla-2-5-26-released.html\">2.5.26<\/a>).<\/p>\n<p>Joomla is among the software GoDaddy lists as being the five most popular in the Hosting Connection and unfortunately isn&#8217;t the only one where they have failed to keep up with security updates. They are currently installing\u00a0Simple Machines Forum version 2.0.6:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/SimpleMachinesForum.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2214\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-simple-machine-forum.png\" alt=\"GoDaddy's Hosting Connectin is installing Simple Machine Forum 2.0.6\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-simple-machine-forum.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-simple-machine-forum-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>Version 2.0.9, which was <a href=\"http:\/\/www.simplemachines.org\/community\/index.php?topic=528448.0\">released<\/a> over a month ago, addressed\u00a0&#8220;several security issues&#8221; and the developers recommended\u00a0&#8220;that you update your forums immediately to ensure that your community is safe&#8221;.<\/p>\n<p>Looking at other software we work with frequently we found more problems. GoDaddy is still offering MediaWiki 1.21.1:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/MediaWiki.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2219\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-mediawiki.png\" alt=\"GoDaddy's Hosting Connectin is installing MediaWiki 1.2.1.1\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-mediawiki.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-mediawiki-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>Support for the MediaWiki 1.21.x series <a href=\"http:\/\/www.mediawiki.org\/wiki\/Version_lifecycle#Versions_and_their_end-of-life\">ended back in June<\/a>, so GoDaddy should have switch to a newer series by that point. Before that though they failed to update\u00a0for any of the nine security updates\u00a0(<a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2013-September\/000133.html\">1.21.2<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2013-November\/000135.html\">1.21.3<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-January\/000138.html\">1.21.4<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-January\/000140.html\">1.21.5<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-February\/000141.html\">1.21.6<\/a>,<a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-March\/000145.html\"> 1.21.8<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-April\/000149.html\">1.21.9<\/a>, <a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-May\/000151.html\">1.21.10<\/a>, and\u00a0<a href=\"https:\/\/lists.wikimedia.org\/pipermail\/mediawiki-announce\/2014-June\/000155.html\">1.2.11<\/a>) released for the 1.21.x series.<\/p>\n<p>Next up, GoDaddy is still offering OpenX despite it being re-branded as Revive Adserver over a year ago:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/OpenX.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2218\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-openx.png\" alt=\"GoDaddy's Hosting Connectin is installing OpenX 2.8.3\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-openx.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-openx-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>The version they are offering is nearly five years out of date, the next version was <a href=\"http:\/\/openx.com\/blog\/openx-284-is-available-for-download\/\">released in January of 2010<\/a>, and they fail to update for the last eight security updates (2.8.6, 2.8.7, 2.8.8, 2.8.9, 2.8.10, <a href=\"http:\/\/www.revive-adserver.com\/blog\/whats-new-in-revive-adserver-v3-0-0\/\">3.0.0<\/a>, <a href=\"http:\/\/www.revive-adserver.com\/blog\/revive-adserver-v3-0-2-released-important-security-fix\/\">3.0.2<\/a>, and <a href=\"http:\/\/www.revive-adserver.com\/blog\/revive-adserver-v3-0-5-released\/\">3.0.5<\/a>).<\/p>\n<p>For Moodle they are still providing Moodle 1.9.19:<\/p>\n<p><a href=\"https:\/\/hostingconnection.godaddy.com\/Application\/Moodle.aspx\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2220\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-moodle.png\" alt=\"GoDaddy's Hosting Connectin is installing Moodle 1.9.19\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-moodle.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/11\/godaddy-hosting-connection-moodle-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>That was the last release of the Moodle 1.9.x series, for which support for security fixes ended entirely <a href=\"https:\/\/docs.moodle.org\/dev\/Releases#Moodle_1.9\">last December<\/a>. Anyone unlucky enough to install this version and start using it now would discover they will have a lot of work to get it to a supported version as the upgrade from Moodle 1.9.x to 2.x is a major one and they will have to do at least two upgrades as you have to an intermediate upgrade 2.2.x before getting to a supported version.<\/p>\n<h2>GoDaddy&#8217;s\u00a0Partnership with SiteLock<\/h2>\n<p>It gets worse from there,\u00a0while GoDaddy is putting their client&#8217;s websites at risk they then want to sell them\u00a0<a href=\"https:\/\/www.godaddy.com\/security\/malware-scanner.aspx?ci=89165\">additional service<\/a> to &#8220;Defend your website against hackers.&#8221;, which is done in <a href=\"https:\/\/www.godaddy.com\/news\/article\/godaddy-offers-complete-website-security-through-sitelock.aspx\">partnership with SiteLock<\/a>. We would ask how it is that SiteLock hasn&#8217;t informed them about the issue with outdated software but our past experience is the SiteLock doesn&#8217;t do the <a title=\"SiteLock Fails To Do Basic Security Check\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/03\/sitelock-fails-to-do-basic-security-check\/\">basic security check of making sure the software on a website is up to date<\/a>, which would expect from a company that GoDaddy <a href=\"https:\/\/www.godaddy.com\/news\/article\/godaddy-offers-complete-website-security-through-sitelock.aspx\">says<\/a> provides the &#8220;most advanced and complete security solution available&#8221;, or <a title=\"SiteLock Doesn\u2019t Do Basic Part of Proper Hack Cleanup\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/25\/sitelock-doesnt-do-basic-part-of-proper-hack-cleanup\/\">make sure that software gets updated when they clean up a hacked website<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Oftentimes when a website is hacked the\u00a0web host will blame the hack on outdated software running on the website. From our experience they often do this without any evidence to back that up and in some cases they obviously haven&#8217;t even checked if the website is running outdated software since the website in question was &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/11\/13\/godaddy-distributing-software-with-known-security-vulnerabilities\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GoDaddy Distributing Software With Known Security Vulnerabilities&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,35],"tags":[],"class_list":["post-2210","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-outdated-web-software"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2210"}],"version-history":[{"count":4,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2210\/revisions"}],"predecessor-version":[{"id":2222,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2210\/revisions\/2222"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}