1
nutthakorn
My xoops's website was hacked !
  • 2008/3/16 16:54

  • nutthakorn

  • Just popping in

  • Posts: 1

  • Since: 2008/3/16


There 's the hacker hack my website.

When ever I upgrade to XOOPS 2.0.18.1 RC, the hacker can hack my website again. (I already change the ftp password and found that he still can hack my web!)

Last week, the hacker try to upload phishing paypal.com on my website too ( He upload under folder module) ! I alraedy delete it.

This is my server details :

OS : Linux
CMS : XOOPS 2.0.18.1 RC
Module
- filemanager Version 3
- iContent version 4.5
- protector version 2.52
- XOOPS stat version 0.45

These are file of Hacker

1. mini.php found in "/module"
2. B.txt found in "/module/togot"
3. morgan.txt found in "/module/togot"
4. proxy.tgz found in "/module/togot"
5. psy.tgz found in "/module/togot"

The folder "togot" created by Hacker

Can anybody help me to protect my website ?

2
McDonald
Re: My xoops's website was hacked !
  • 2008/3/16 17:04

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


First upgrade to XOOPS 2.0.18.1 final.

Second, do not use iContent 4.5 because it is vulnerable like any module using Spaw editor, see here.

3
Anonymous
Re: My xoops's website was hacked !
  • 2008/3/16 17:49

  • Anonymous

  • Posts: 0

  • Since:


Quote:

McDonald wrote:
First upgrade to XOOPS 2.0.18.1 final.

Second, do not use iContent 4.5 because it is vulnerable like any module using Spaw editor, see here.


Third, upgrade to Protector v3.04 or 3.16b

4
avtx30
Re: My xoops's website was hacked !
  • 2008/3/16 22:23

  • avtx30

  • Not too shy to talk

  • Posts: 181

  • Since: 2006/10/12


Do not use filemanager. It's said to be a low-quality module.

Login

Who's Online

462 user(s) are online (79 user(s) are browsing Support Forums)


Members: 0


Guests: 462


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Oct 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits