11
MinnesotaW
It's back!!
  • 2007/8/25 16:51

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Woohoo...it's back.

I finally got back to the admin page, and the blocks that were visible all had 0's in the left block column, so I renumberd the blocks, saved it, boom the site reappeared!

Right now I have no idea how it happened as other than running XOOPS care on it's own, I've not been into the database at all lately.

Very strange, db related for sure, and I want to thank the members that responded helping me poke around the site.



12
MinnesotaW
Re: Site Hacked, look at the script they used and help!
  • 2007/8/25 16:11

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

McDonald wrote:
EDIT:
When somebody hacks a site they normally leave something behind (a message or files). Speaking about files, did you check if somebody stored big files somewhere?
This happened ones with my site where somebody placed some big movie files in a folder. It slowed down my site first until it crashed.


I've been through the entire directory structure looking for altered or new files, and the only thing with todays date was in the cache folder.

We only allow photos with a max size restriction put on and looking in upload there isn't anything in there that is big in size.

In _users in the db there were 2 new entries user23423 and user9846 and new users on the site need to be approved, and we reject anyone that submits a userid like that.



13
MinnesotaW
Re: Site Hacked, look at the script they used and help!
  • 2007/8/25 16:04

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

skenow wrote:
The database may be there, but it does not sound like it is the way you left it - incorrect password = altered database; blocks missing and modules not installed = altered database, too.

I would:
1. change your database user/password immediately
2. determine if the root user for the database has a password and create one if it doesn't
3. determine if there is an anonymous user that can access the database and remove it if it does exist
4. remove any other database users
5. determine if phpmyadmin can access the db without entering a username/password - change it if it can
6. find your most recent database backup before the hack was noticed and be ready to restore it


1. Done
2. it does, always has
3. all tools my provider (Ipower) has for me I cannot see
4. only 1 db user, that's all I've ever had
5. phpmyadmin doesn't let you in without the valid userid/pwd...bogus or blank is rejected
6. yeah...I thought that might be the answer

Appreciate the suggestions, I'll let you know how it comes out.



14
MinnesotaW
Re: Site Hacked, look at the script they used and help!
  • 2007/8/25 15:43

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

skenow wrote:
That script does look valid, as McDonald says.

Can you access any part of your site? login at /user.php, register at /register.php, administration menu at /admin.php

Check your database, it may be the problem - module installation status is stored in the database. If files were missing, you would get 404 errors instead of not installed.


Right now I cannot access anything on the site, database seems all there, and the directory structure is still intact on the webserver.

When I attempted to get on this AM, the site looked normal, I tried to logon and it stated incorrect password...then the login block disappeared, then the news block disappeared (as I clicked around), then gallery, etc...



15
MinnesotaW
Re: Site Hacked, look at the script they used and help!
  • 2007/8/25 15:39

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

McDonald wrote:
I don't think this script is a hack!

Normally there's a file called adminmenu.php placed in the cache folder on XOOPS 2.0.x websites.

This script is different per site because of the different modules users install.

Probably it's better to put the script back in your cache folder and check if any other files are modified.

Make in the mean time a backup of your database if possible.


Bummer...it's the only file in the entire directory with a date even close to today!

I think I'm hosed...backup the db isn't a problem and that I can do.

If you'd like to peek at this,http://www.vetteaction.com

Clicking on anything has a "this module not active" message, and for a while the entire site disappeared!



16
MinnesotaW
Re: Site Hacked, look at the script they used and help!
  • 2007/8/25 15:07

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Where I'm at right now...no modules "exist" according to clicking on the site.

Anyone? 53 views and no suggstions



17
MinnesotaW
EDIT: Site messed up, help!
  • 2007/8/25 13:08

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Hi all...yeah...for some odd reason I had the incorrect permissions on my cache folder and I got hacked, here is the file they installed in cache to help shut the site down, and what exactly changed? (I'm good at kicking PHP tires but that's about all)

EDIT...

Helpful folks have pointed out the script is something created by xoops...excuse my noobieness to PHP



18
MinnesotaW
Re: CBB 3.08 next post/previous post buttons...
  • 2007/3/4 14:15

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

irmtfan wrote:
huum maybe clear xoops_session table can help you
installing xoopscare make it easier.


Yep...already have that and have done it.

Time to code dive I guess...



19
MinnesotaW
Re: CBB 3.08 next post/previous post buttons...

Quote:

JAVesey wrote:
The buttons behave as expected.

Sorry, but I can't help more and my tech knowledge isn't the best.


Yup on your site they do behave properly for me too.

Thanks for looking John...



20
MinnesotaW
Re: CBB 3.08 next post/previous post buttons...
  • 2007/3/1 22:39

  • MinnesotaW

  • Just popping in

  • Posts: 38

  • Since: 2007/1/22


Quote:

JAVesey wrote:
Me neither.

All works swimmingly.


Really?

I logged out to see if it was for some reason being logged in (so I'd surf like you are) and it still jumped for me.

So if I understand correctly, you are saying it's an IE 7 issue?




TopTop
« 1 (2) 3 4 »



Login

Who's Online

120 user(s) are online (55 user(s) are browsing Support Forums)


Members: 0


Guests: 120


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits