Ask Questions and Find Answers
Important:
Ask is now read-only. You can review any existing questions and answers, but not add anything new.
But - don't panic! While ask is no more, we've replaced it with discuss - the new Liferay Discussion Forum! Read more here here or just visit the site here:
discuss.liferay.com
RE: Please help me on Security related issue
Hi Team,
I am using liferay-ce-portal-7.1.0-ga1 version in one of my web application, I found "kinsing-*" unknown folder in liferay-ce-portal-7.1.0-ga1/tomcat/bin folder and attached the screenshot please check once. please help me to restrict this type of attacks.
Thank you in advance.
I am using liferay-ce-portal-7.1.0-ga1 version in one of my web application, I found "kinsing-*" unknown folder in liferay-ce-portal-7.1.0-ga1/tomcat/bin folder and attached the screenshot please check once. please help me to restrict this type of attacks.
Thank you in advance.
Attachments:
Jagan Mohan:
Please read https://liferay.dev/blogs/-/blogs/security-patches-for-liferay-portal-6-2-7-0-and-7-1 and keep an eye on future upgrades. Note that typically updates are provided for the latest GA release, and you should follow along, planning to go towards 7.3 soon, but the first step would be to go to 7.1 GA4 plus patch.
I am using liferay-ce-portal-7.1.0-ga1 version in one of my web application, I found "kinsing-*" unknown folder in liferay-ce-portal-7.1.0-ga1/tomcat/bin folder and attached the screenshot please check once. please help me to restrict this type of attacks.
If you need a long-term stable release without the need to upgrade to newer GAs/versions (but with provided fixpacks to a stable version), consider Liferay DXP instead of Liferay Portal CE.
One thing you should do is to run liferay as a non-root user with no permissions to write on those folders.
Also, in line with Olaf's suggestions, take a look at https://liferay.dev/blogs/-/blogs/creating-liferay-security-binary-patches
HTH
Fernando
Also, in line with Olaf's suggestions, take a look at https://liferay.dev/blogs/-/blogs/creating-liferay-security-binary-patches
HTH
Fernando