Yesterday, we received the final investigation report from JPCERT/Coordination Center.
How unauthorized hacking was happened
From the various remained access logs, we could not identify the cause for the unauthorized hacking. We confirmed suspicious accesses (web and ftp) from 203.194.144.#, and we confirmed traces of attack attempts in early August. However, we couldn’t identify how the hacker entered our site just by these traces. There were no successful logins from these IP addresses.
About unauthorized redirects
From the remained access logs, the following 2 accesses were considered unauthorized accesses redirected by the .htaccess that was placed by a hacker.
#.#.#.# - - [18/Aug/2014:05:41:38 -0500] "GET /pub/updates/emed64_updates_ja.txt HTTP/1.1" 200 884 "-" "AdvancedInstaller"
#.#.#.# - - [18/Aug/2014:06:19:04 -0500] "GET /pub/updates/emed64_updates_ja.txt HTTP/1.1" 200 884 "-" "AdvancedInstaller"
These accesses match with the IP addresses written in the .htaccess, the time frame when the incident happened. Also, the number of bytes written in the access log (884) was different from the number of bytes written in the other accesses in the other time frame and other IP addresses.
Usually access logs look like:
#.#.#.# - - [10/Aug/2014:03:45:09 -0500] "GET /pub/updates/emed64_updates_ja.txt HTTP/1.1" 200 855 "-" "AdvancedInstaller"
the number of bytes is 855 for this file, but the above two accesses show the number of bytes as 884 bytes.
The clients who own the above IP addresses were contacted by JPCERT/CC, and found there were no malware infections. The access logs record all accesses including merely update checking without actual installation.
Future measures
In addition to routine updates of WordPress plug-ins and themes, we periodically scan our site for malware, monitor files on the server, access logs, and block suspicious IP addresses. On August 29th, we protected the entire site of emeditor.com with SSL encrypted connections. We are also planning to move our forums to another site or an electronic mailing list for improved security.
The next version of Advanced Installer that we used to make the Update Checker will be able to block update installers without the same digital signature as ours. The future EmEditor versions will restore the Update Checker with improved security.
We apologize for any inconveniences that this situation might have caused you
See also:
Possible malware attack by EmEditor Update Checker
EmEditor v14.6.0 released!
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor v14.6.0.
This new version adds important features with big data analysis and database file editing in mind.
Updates from v14.5.4 include:
New General Features
quotes, whether to allow new lines in double quotes, and the number of lines in the column headings.
Delete Duplicate Lines command, Line
Number, Ruler, and Heading commands.
Convert to commands,
Fixed Width Columns, all sort commands, Delete Duplicate Lines, Heading 0 – 4, Adjust Separator Positions, Automatically Add Separators, and
Remove All Separators.
pressing the mouse button selects multiple columns.
Bug Fixes
Please see EmEditor v14.6 New Features for details.
The Update Checker on older versions of EmEditor will not be available anymore. If you try to check updates from older versions, you will see the prompt message: “Invalid or missing updates configuration file. …”. This is not a bug. Please download and update to the newest version of EmEditor by clicking here.
Download EmEditor v14.6 Now.
V14 is free upgrade from v13. To use v14, you will need a v14 registration key. If you have valid v13 licenses, you can view your free v14 registration keys at Emurasoft Customer Center.
80% of our customers (including old customers who have registered their products) already have lifetime licenses. Even if you haven’t installed v13, please click the above link to check if you can upgrade to v14.
Please also read: Announcing our policy change to rapid development, and introducing a maintenance plan.
Thank you for using EmEditor.
New Video: EmEditor v14.6 new features
/in EmEditor Core/by Yutaka EmuraToday, we created the video for EmEditor v14.6 new features: Enhanced CSV features, Filter Bar, Sort by Multiple Columns.
We will release v14.6 soon.
Thank you for using EmEditor!
Version 14.6 feature page was added
/in EmEditor Core/by Yutaka EmuraToday, we added the EmEditor Version 14.6 feature page. This new version adds important features with big data and database files in mind: more CSV support, Filter Bar, more Search options including the Extract button. We are planning to release EmEditor Version 14.6 very soon.
Thank you for using EmEditor!
Switching to Avangate
/in General/by Yutaka EmuraWe are excited to announce that we are switching our online payment partner to Avangate. Our customers will appreciate more features including telephone support in many counties, the ability to control the renewal option during check-out as well as the new fresh user interface. Optional Backup CD and Download Insurance Service are now unselected by default.
If you experience any issues during the checkout, please don’t hesitate to contact us. We always value your feedback.
Thank you.
EmEditor v14.6.0 beta 17 released!
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor v14.6.0 beta 17.
Updates from v14.6.0 beta 16 include:
We would like to find as many bugs as possible before we release the new version. Please try it out now and let us know if you find any bugs.
To download or see changes, please go to the beta forum – EmEditor Professional v14.6.0 beta 17 released!.
Thank you for continue using EmEditor!
Investigation report about the hacking incident
/in General/by Yutaka EmuraYesterday, we received the final investigation report from JPCERT/Coordination Center.
How unauthorized hacking was happened
From the various remained access logs, we could not identify the cause for the unauthorized hacking. We confirmed suspicious accesses (web and ftp) from 203.194.144.#, and we confirmed traces of attack attempts in early August. However, we couldn’t identify how the hacker entered our site just by these traces. There were no successful logins from these IP addresses.
About unauthorized redirects
From the remained access logs, the following 2 accesses were considered unauthorized accesses redirected by the .htaccess that was placed by a hacker.
These accesses match with the IP addresses written in the .htaccess, the time frame when the incident happened. Also, the number of bytes written in the access log (884) was different from the number of bytes written in the other accesses in the other time frame and other IP addresses.
Usually access logs look like:
the number of bytes is 855 for this file, but the above two accesses show the number of bytes as 884 bytes.
The clients who own the above IP addresses were contacted by JPCERT/CC, and found there were no malware infections. The access logs record all accesses including merely update checking without actual installation.
Future measures
In addition to routine updates of WordPress plug-ins and themes, we periodically scan our site for malware, monitor files on the server, access logs, and block suspicious IP addresses. On August 29th, we protected the entire site of emeditor.com with SSL encrypted connections. We are also planning to move our forums to another site or an electronic mailing list for improved security.
The next version of Advanced Installer that we used to make the Update Checker will be able to block update installers without the same digital signature as ours. The future EmEditor versions will restore the Update Checker with improved security.
We apologize for any inconveniences that this situation might have caused you
See also:
Possible malware attack by EmEditor Update Checker
New Filter Bar feature: (EmEditor Professional v14.6.0 beta 11)
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor Professional v14.6.0 beta 11.
Updates from v14.6.0 beta 8 include:
We would like to find as many bugs as possible before we release the new version. Please try it out now and let us know if you find any bugs.
To download or see changes, please go to the beta forum – EmEditor Professional v14.6.0 beta 11 released! (New Feature: Filter Bar).
Thank you for continue using EmEditor!
EmEditor Professional v14.6.0 beta 8 released!
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor Professional v14.6.0 beta 8.
Updates from v14.6.0 beta 4 include:
We would like to find as many bugs as possible before we release the new version. Please try it out now and let us know if you find any bugs.
To download or see changes, please go to the beta forum – EmEditor Professional v14.6.0 beta 8 released!.
Thank you for continue using EmEditor!
EmEditor Professional v14.6.0 beta 4 released!
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor Professional v14.6.0 beta 4.
Updates from v14.6.0 beta 1 include:
We would like to find as many bugs as possible before we release the new version. Please try it out now and let us know if you find any bugs.
To download or see changes, please go to the beta forum – EmEditor Professional v14.6.0 beta 4 released!.
Thank you for continue using EmEditor!
EmEditor Professional v14.6.0 beta 1
/in EmEditor Core/by Yutaka EmuraToday, we are releasing EmEditor Professional v14.6.0 beta 1.
We used to use terminology “Separated Values” or “CSV/DSV/TSV”, but we will start calling all separated values by any delimiters as “CSV”.
Updates from v14.5.4 include:
We would like to find as many bugs as possible before we release the new version. Please try it out now and let us know if you find any bugs.
To download or see changes, please go to the beta forum – EmEditor Professional v14.6.0 beta 1 released!.
Thank you for continue using EmEditor!