1
sharanu
Xoops hacked - Admin login not working
  • 2007/6/29 2:57

  • sharanu

  • Just popping in

  • Posts: 6

  • Since: 2007/1/10


Hi,

My website has been hacked. I was using phpmailer and xoops. I am not getting the admin menus. Some "Guide_shen" has hacked it.

How to recover? Any help appreciated.

Thanks

2
phppp
Re: Xoops hacked - Admin login not working
  • 2007/6/29 3:29

  • phppp

  • XOOPS Contributor

  • Posts: 2857

  • Since: 2004/1/25


Is "not getting the admin menus" the only problem? Can you get more details?
Do you have server logs?

3
sharanu
Re: Xoops hacked - Admin login not working
  • 2007/7/6 3:07

  • sharanu

  • Just popping in

  • Posts: 6

  • Since: 2007/1/10


Actually complete website was not accessible. ssh/ftp account was also changed. However I could get that corrected.

Now, I am not able to login as admin, no admin menus and no modules are showing up. Any admin functionality is not working.

How do i get server logs?

- Sharan.

4
BlueStocking
Re: Xoops hacked - Admin login not working

What is the site url? (address)
I want to google (cache) and see what you had before you were hacked.

Next question: did/does your host server make backups on a regular basis as mine does?

Can you get to your files on your fileserver?
hhttps://xoops.org/modules/repository .. It is time to get involved - XOOPS.ORG

5
Catzwolf
Re: Xoops hacked - Admin login not working
  • 2007/7/6 4:06

  • Catzwolf

  • Home away from home

  • Posts: 1392

  • Since: 2007/9/30


First, if you are on a shared server, the attack was most likely server wide and just not you specificaly. I know that doesn't make you feel any better though.

First thing to do is change all your passwords within your web hosting panel FTP/Mysql and change them to something that will be hard to guess or crack.

Secondly, the attack was most likely done via your 'upload' folder, look in there for anything that maybe a little suspicious and delete it.

Next, purge/delete the following folders in your XOOPS root.

a. cache
b. templates_c

Once you have done that and if that gets you back into your Xoops, please take the next steps.

a. Upgrade to the lastest version of XOOPS (If you haven't already done so) and upgrade your system module.
b. If you can, Chmod the following folders to 755 (If your server allows this)
1. cache,
2. templates_c,
3. uploads.
c. Install Protector module.
d. Change your XOOPS account password.
e. Check the XOOPS FAQ about securing your XOOPS further.
f. Look to see if any of the modules you have installed have updates or there as been any security issues poested about them, you may find some bugfixes around XOOPS somewhere.

Let us know how you get on please :)

Regarding your server logs, you can obtain these via your webhosting cpanel. Contact their support and they should help you with that.
ATB

Catz

6
BlueStocking
Re: Xoops hacked - Admin login not working

Catz,
Thanks for a lot of good information there. Appreciate it!
hhttps://xoops.org/modules/repository .. It is time to get involved - XOOPS.ORG

7
Catzwolf
Re: Xoops hacked - Admin login not working
  • 2007/7/6 5:48

  • Catzwolf

  • Home away from home

  • Posts: 1392

  • Since: 2007/9/30


Quote:

BlueStocking wrote:
Catz,
Thanks for a lot of good information there. Appreciate it!


Anytime, I hope that it helps someone as it has saved me a few times :)

ATB

Catz

Login

Who's Online

363 user(s) are online (89 user(s) are browsing Support Forums)


Members: 0


Guests: 363


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Oct 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits