1
Ventrix
plz help someone hacked me
  • 2004/8/31 10:46

  • Ventrix

  • Just popping in

  • Posts: 58

  • Since: 2004/8/31


Someone hacked my web hosting account. I had phpbb2 and xoops. He changes the sending registration e-mail of my phpbb2 but suddently the e-mail registration from XOOPS now sends (the same) bad things at anyone who registers. Help me plz!

2
Jan304
Re: plz help someone hacked me
  • 2004/8/31 11:58

  • Jan304

  • Official Support Member

  • Posts: 520

  • Since: 2002/3/31


Can you check the logs and check for weird things?

I don't think the fault lays with xoops, since to modify the registration e-mail you have to get file access... I think it's better that you contact you host and notify them about this problem.

3
JMorris
Re: plz help someone hacked me
  • 2004/8/31 12:03

  • JMorris

  • XOOPS is my life!

  • Posts: 2722

  • Since: 2004/4/11


If you haven't already done so, close your site to the public and upgrade your site to v2.0.7.1. This version fixes know vulnerabilities in Xoops.

After you've successfully upgraded your site, log into your FTP account and chmod all folders on XOOPS to 555.

Exceptoins:
chmod the following as 777
/cache
/templates_c
/uploads

chmod the following 444
mainfile.php

If you're not familiar with chmod, here's what the values mean:

777 = read/write/excecute by all
555 = read/excecute by all
444 = read by all

You should also check the phpBB site / documentation to ensure that your forum is the most recent version, and the permissions on your forum's files are correct. The controls in the Admin panel are not the only factors you need to consider.

This kinda thing is more common on shared hosting plans, so as mentioned above, contact your host.

4
DonXoop
Re: plz help someone hacked me

But also understand that the cracker more than likely has root access and is able to cause havoc with any file on the server. You mention that your XOOPS and phpbb sites were both hacked. I'll bet other user's sites were cracked too.

Tighten up XOOPS for sure but don't think that it can't happen again if the server itself is at risk still.

Watch those logs.

5
Ventrix
Re: plz help someone hacked me
  • 2004/8/31 12:31

  • Ventrix

  • Just popping in

  • Posts: 58

  • Since: 2004/8/31


How can i see my XOOPS version and where to download the updated version? (if need to)

6
Herko
Re: plz help someone hacked me
  • 2004/8/31 13:00

  • Herko

  • XOOPS is my life!

  • Posts: 4238

  • Since: 2002/2/4 1


You can find the version number in the bottom of your admin control panel. The latest version can be found here on xoops.org, just follow the big red link at the top of the homepage.

Herko

Login

Who's Online

252 user(s) are online (175 user(s) are browsing Support Forums)


Members: 0


Guests: 252


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits