1
Stitch19
My site has been hacked again !!!
  • 2005/1/31 12:55

  • Stitch19

  • Just popping in

  • Posts: 81

  • Since: 2004/12/18


If you remember me my site have been hacked again, but this time the hacker finds the admin passwords enter the site and at the index add pornographic photos...also he has found my hotmail and changed the password and now i lost my hotmail and msn account that i have been usind for the last 2 years.
So my XOOPS is v. 2.0.9.2 ... and the hacker have attacked the site twice in one day.
So i lost my hotmail the hacker finds my pssword for the site even if i change it every 1 hour. So am i gonna shoot my self with a gun or just to close down my site ???

is there any module thats add more security to the acounts or to the hole site??????

2
terrion
Re: My site has been hacked again !!!
  • 2005/1/31 13:06

  • terrion

  • Friend of XOOPS

  • Posts: 299

  • Since: 2004/9/19


This is terrible and I'm very sorry for your loss.

I've never run this script but think I'm going to install it right now. It's Xoops Protector and is available in the Module Repository under the security link. There's been lots of good stuff posted about this module in the support forums.

Good luck, and hope you get everything back to normal.

3
jdseymour
Re: My site has been hacked again !!!

I also recommend the XOOPS Protector. I use it myself. Although nothing can protect completely from a determined cracker the protector can surely make it harder for the less talented.

4
Stitch19
Re: My site has been hacked again !!!
  • 2005/1/31 13:26

  • Stitch19

  • Just popping in

  • Posts: 81

  • Since: 2004/12/18


Ok i will try that module, but it seems to me that the hacker will do it until he gets bored or until he destroyes completly the site...
Very nice...
what i have done to be attacked by 2 hacker in 1 month...

5
kiwiguy
Re: My site has been hacked again !!!
  • 2005/1/31 13:44

  • kiwiguy

  • Friend of XOOPS

  • Posts: 295

  • Since: 2004/4/19


Hey Stitch sorry to hear whats happened I have XOOPS Protector installed and it pretty much will make it harder but will not distract a determined hacker.

My only suggestion is if you have cpanel you can password protect your site like that for a while and only give the password and login details to your current trusted members for the time being say a month hopefully the hacker will get bored and move on.

regards
kiwiguy

6
jdseymour
Re: My site has been hacked again !!!

One other suggestion, make sure mainfile.php is chmod 444. You may need to make the changes through the cPanel filemanager as I cannot get that setting to stick through ftp.

7
DonXoop
Re: My site has been hacked again !!!

I don't think Protector is going to cure the problem. Suggest installing it but he has other problems. His hotmail account is getting compromised, unless that password is stored in XOOPS that will keep getting nailed. The cracker will more than likely keep coming in without triggering Protector.

Protector isn't going to protect against a poor config or poor server security. How is the hotmail account getting nailed "every hour"? Clearly something else is going on.

FYI, if you do install Protector you should watch it closely or you might end up with 100s of pages of "violations" that really aren't. Some modules like chat apps will trigger protector and cause other grief. You have to start at the server and move up until you finally protect the site that is as secure as it can be already.

8
jdseymour
Re: My site has been hacked again !!!

Maybe weak passwords, and a brute force attack?

9
jdseymour
Re: My site has been hacked again !!!

Hi Stitch19,

Another thing to think about is that it could possibly be someone on the inside of your site. Does anyone else have access to these accounts?

Login

Who's Online

267 user(s) are online (208 user(s) are browsing Support Forums)


Members: 0


Guests: 267


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits