I need a help PLZ :every file named index has been injected ...
#1
Just popping in
Just popping in


See User information
Hello,

I need a help plz,so I checked my domain today and found an error on my index.php page. When I checked the page I found that a code has been injected. Here is the code:



[EDIT by Mamba]I've replaced the domain name of the hacker, as Ghia suggested

I checked the rest of my domain and found out that every file named index has been injected with the same code, so all my index.php and index.html have been changed.

how can I remode this virus from my XOOPS site :(

Posted on: 2009/1/11 21:48
 Top  Twitter  Facebook    Linkedin  Del.icio.us  Digg  Reddit  Mr. Wong 


Re: I need a help PLZ :every file named index has been injected ...
#2
Community Support Member
Community Support Member


See User information
Your site has been hacked. This can be due to a security failure of XOOPS, on your PC or of your hosters server. Contact your hoster for the last case.

It is important to find out how the hacker managed to get access. Check out your logs. Delete the files on your site and replace them from a recent backup. Update your site to recent and stable versions. Inspect your database for sneaky data. Change all your passwords and check all the users that manage the site on all levels (MySQL, FTP XOOPS webmasters and privileged groups). Read the advices given in some threads about hacked sites (follow show all) and the security News.

PS: Don't publish SPAM domains!

Posted on: 2009/1/11 22:27
 Top  Twitter  Facebook    Linkedin  Del.icio.us  Digg  Reddit  Mr. Wong 


Re: I need a help PLZ :every file named index has been injected ...
#3
Community Support Member
Community Support Member


See User information
Hi,

on top of what ghia said you may post a list of used modules with versions and get some info on security treats and problems...

clear the template cache and check webmaster group for new members...

Posted on: 2009/1/11 22:34
..
 Top  Twitter  Facebook    Linkedin  Del.icio.us  Digg  Reddit  Mr. Wong 


Re: I need a help PLZ :every file named index has been injected ...
#4
Module Developer
Module Developer


See User information
The exact same thing happened to me several months ago. The hacker managed to access and get a dump of my username and password list for the site. The password I was using to administer the site was the same password I used to access ftp.

I would suggest either looking at your server's ftp log or ask your host provider to look at the log. Even if you have to keep a hand written list of passwords I recommend never using the same password twice.

And when it comes to beefing up security for the future you should follow the advice of folks like ghia. He was fantastic at helping me work through my issues.

Posted on: 2009/1/11 23:00
 Top  Twitter  Facebook    Linkedin  Del.icio.us  Digg  Reddit  Mr. Wong 


Re: I need a help PLZ :every file named index has been injected ...
#5
Moderator
Moderator


See User information
Quote:
Even if you have to keep a hand written list of passwords I recommend never using the same password twice.

Absolutely agree! And with tools like http://keepass.info/ that generate and keep passwords for you, there is really no excuse for not doing it.

Quote:
And when it comes to beefing up security for the future you should follow the advice of folks like ghia. He was fantastic at helping me work through my issues.

Yep, Ghia is D'Man!!! As a community we're so lucky to have him!!!

Posted on: 2009/1/12 0:38
Support XOOPS => DONATE
Use 2.5.11 | Docs | Modules | Bugs
 Top  Twitter  Facebook    Linkedin  Del.icio.us  Digg  Reddit  Mr. Wong 







You can view topic.
You cannot start a new topic.
You cannot reply to posts.
You cannot edit your posts.
You cannot delete your posts.
You cannot add new polls.
You can vote in polls.
You cannot attach files to posts.
You cannot post without approval.
You cannot use topic type.
You cannot use HTML syntax.
You cannot use signature.
You cannot create PDF files.
You cannot get print page.

[Advanced Search]


Login
Username:

Password:

Remember me



Lost Password?

Register now!
Search
Recent Posts
Who's Online
194 user(s) are online (89 user(s) are browsing Support Forums)

Members: 0
Guests: 194

more...
Donat-O-Meter
Make donations with PayPal!
Stats
Goal: AU$15.00
Due Date: May 31
Gross Amount: AU$0.00
Net Balance: AU$0.00
Left to go: AU$15.00
Latest GitHub Commits
Recent forum posts
Recent Comments
About us
Learn
Use
Develop GitHub
Contribute
Connect
Terms of Use | Privacy Policy | Hosted by Arvixe Hosting | RSS 2.0 Button