1
harvester
I was hacked. Please help
  • 2005/4/3 22:04

  • harvester

  • Just popping in

  • Posts: 19

  • Since: 2004/9/28


I have a fairly popular gaming site that generates a decent amount of traffic. About 3 days ago I logged in to update the news and I noticed that someone had hacked in and was in the prosses of changing all my front page news posts to racial slurs and gay porn. He had already deleted all the forum posts and sent out a mass e-mail to all my registerd members (about 3,500) The e-mail was very hate oriented. The guy that hacked in clamed to be a member of myg0t. I shut down my vps to prevent any more damage. I did not have a recent backup of the MySQL database so I had to roll back the forums to a version over 2 months old.
My question is: How easy was it for him to hack into my page?
Is there anything that I can do to try and prevent a future attack?
I had the mainfile.php and admin.php files permissions set to 644, I have now changed them to 444.

I don't know about hacking so i'm not sure how he got into my site or how I can try and prevent him or somebody else from hacking in. I'm afraid to bring the page back online untill I can get the page secured. any help will be greatly appreciated.
Thank you.

2
jdseymour
Re: I was hacked. Please help

Sorry to hear about your troubles. It is imposible to completely prevent a determined cracker from doing his bad things. There are several things that you can do to help make it harder.

1. Strong Admin Passwords. Now cats name dog name sons birthday. But a real password with letters and numbers, uper case and lower case.

2. When installing XOOPS set another prefix besides the default xoops_.

3. Stay up to date with all security fixes.

4. Use the Protector Module by GIJOE. This module also has the ability to change your database prefix almost automatically (you will need to edit mainfile.php the prefix change)

Like I said these do not completely eliminate your site being attacked or hacked but it will make it harder for a determined one to do, and probably discourage script kiddies also.

HTH.

3
tjnemez
Re: I was hacked. Please help
  • 2005/4/3 22:19

  • tjnemez

  • Home away from home

  • Posts: 1594

  • Since: 2003/9/21


not sure what version of XOOPS you are using, but the newest update has addressed some security issues and you can also install gi joe's protector module. get it here:
http://www.peak.ne.jp/xoops/modules/mydownloads/

do a search and read some of the posts related to protector.

4
m0nty
Re: I was hacked. Please help
  • 2005/4/3 22:22

  • m0nty

  • XOOPS is my life!

  • Posts: 3337

  • Since: 2003/10/24


*EDIT* never mind JD beat me to it..

5
LazyBadger
Re: I was hacked. Please help

"Security is not actions, it's process"... If I was read correctly about "VPS" and correctly understand and interpret it - XOOPS was installed on separate box, which have full set of different services (and holes and weakeness). I'm not sure where to start find exploitable entry point - in XOOPS or in the system

6
Josem
Re: I was hacked. Please help
  • 2005/4/4 0:45

  • Josem

  • Just popping in

  • Posts: 18

  • Since: 2004/8/22


I highly recommend if you are running an apache server the module modsecurity and possibly suphp. It could take some effort to set up (depending what you want to use your website for) but it prevents attacks, even attacks we may not know about yet. If you are running the server on your own box, then also chroot apache is a good idea. Of course, right permissions are very important.

7
harvester
Re: I was hacked. Please help
  • 2005/4/4 1:24

  • harvester

  • Just popping in

  • Posts: 19

  • Since: 2004/9/28


Thank you all for your quick responses. I will be looking into all the suggestions. The XOOPS version that I'm using is the latest stable build.

Login

Who's Online

380 user(s) are online (311 user(s) are browsing Support Forums)


Members: 0


Guests: 380


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits