TinyPortal

General => Chit chat => Topic started by: Paulie on April 29, 2006, 01:28:44 PM

Title: Hacked/Defaced
Post by: Paulie on April 29, 2006, 01:28:44 PM
Some sob has hacked/defaced my site.

It looks like a redirect but i have no idea how to get rid of the bugger. I`ve only just got my pc back up and running too, as it fell over big time with my mboard and hdd waving goodbye to me, and now i get this. Gahhhhhhhhhhhhh
Title: Re: Hacked/Defaced
Post by: gerrymo on April 29, 2006, 01:42:44 PM
Yep, you been hacked. But its a server hack, not SMF. Looks like he's replaced your index.php with something else, or just added an index.htm (.htm is before .php when opening the index file). Simply delete [or rename] the file and you should be good to go.

Get your server admin to find how they got in and close the door on them.
Title: Re: Hacked/Defaced
Post by: gerrymo on April 29, 2006, 01:52:28 PM
Just had a look Paulie. Just delete the index.htm file. The site is still working.

http://www.hamburger-deluxe.co.uk/SMF/index.php?action=forum
Title: Re: Hacked/Defaced
Post by: elpvn on April 29, 2006, 01:54:47 PM
Quote from: Paulie on April 29, 2006, 01:28:44 PM
Some sob has hacked/defaced my site.

It looks like a redirect but i have no idea how to get rid of the bugger. I`ve only just got my pc back up and running too, as it fell over big time with my mboard and hdd waving goodbye to me, and now i get this. Gahhhhhhhhhhhhh

Humm , I agree wirh gerrymo, you site has been changed your index.php files (or .htacess file, may be ?)

if you still able to access your server by FTP account then you can change the index.php file in  ;)
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 02:39:30 PM
Paulie it seems to be a redirect hack through TP's shoutbox.

Your site works if no shoutbox is shown as gerrymo showed in
http://www.hamburger-deluxe.co.uk/SMF/index.php?action=forum

If you can go admin mode (it depends if you have bars on or off) disable the shoutbox.
http://www.hamburger-deluxe.co.uk/SMF/index.php?action=admin

You can also  see your site if you disable Java in the browser.

Go to Security update for TP 0.8.6! (http://www.tinyportal.net/smf/index.php?topic=4440.0) download the update and upload it to your server overwriting the old files.

Then you can turn on back the shoutbox.
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 02:49:05 PM
It seems now that you have replaced the index.php without modifications for TP.

Did you overwrite the old index.php or just renamed it? Do you have a backup of it?
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:21:19 PM
Well i just uploaded the two patches into my "Sources" folder and now i cant even get into admin :(

Fatal error: Call to undefined function: tportal_init() in /home/hamburg/public_html/SMF/Sources/Security.php on line 166
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:30:13 PM
If you have a backup stored on the sourse.php and security.php file , try to upload and replace it
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 03:31:55 PM
Paulie did you change the index.php file BEFORE uplloading the update?

It seems like it is an index.php without TP, while the rest are OK.

I had been able to see the hack and your forum working and that you had TP .86 before starting writing my first message. When finished I saw the forum and an error from load.php.
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 03:34:42 PM
G6 I don' t think the problem is in these files. They just try to find TP functions in index.php and can't.
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:37:09 PM
Yes, i just saw that , He should be good to just manually put in the TP codes in the index.php file so it loads up.
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:38:37 PM
Quote from: agridoc on April 29, 2006, 03:31:55 PM
Paulie did you change the index.php file BEFORE uplloading the update?

It seems like it is an index.php without TP, while the rest are OK.

I had been able to see the hack and your forum working and that you had TP .86 before starting writing my first message. When finished I saw the forum and an error from load.php.

No i just uploaded the files.

But my host is going to do a back up for me so, i should be ok lol
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:39:17 PM
Paulie try this index.php file and see if it works for you

Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:39:49 PM
Quote from: G6 on April 29, 2006, 03:37:09 PM
Yes, i just saw that , He should be good to just manually put in the TP codes in the index.php file so it loads up.


Manual :o oooh thats scarey stuff.
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:40:41 PM
Ok hold on ;)
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:45:06 PM
There you go :)

Nice and good looking with the portal active again :)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:47:02 PM
Done, thank you for the helping hand. Do i still need to upload the new patches?
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:47:56 PM
I think it's better to be safe than sorry, so yes :)

And can you activate me there ;)
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 03:49:00 PM
G6 the index.php you sent has the arcade game mod installed. I just did an ASCII compare. I don' t remember if Paulie had .1.1 RC2, I just saw TP which was important to exist for the hack to work.

Paulie if the site works OK I can send you a copy without this mod. Just tell me what SMF version is installed.
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:50:07 PM
I had RC2
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:51:50 PM
I just gave him my index.php to see if it workes to get the blocks back ;)
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 03:52:10 PM
Paulie this is like the one G6 sent to you without the game arcade mod.
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:52:42 PM
Let me just upload the two patches again, and i`ll report back ;)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:53:41 PM
Ok thanks, i`ll do that now.
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 03:54:09 PM
Or just remove those two lines

'arcade' => array('Arcade.php','Arcade'),
      'arcadeadmin' => array('ArcadeAdmin.php', 'ArcadeAdmin'),


//---Start--Erics IPB Game Mod------------------------------

        if ((isset($_REQUEST['act']))&&($_REQUEST['act']=='Arcade'))
        {
              $_REQUEST['action']='arcade';
        }
//---End--Erics IPB Game Mod---------------------------------

//---Start--Erics IPB Game Mod------------------------------

        if ((isset($_REQUEST['act']))&&($_REQUEST['act']=='Arcade'))
        {
              $_REQUEST['action']='arcade';
        }
//---End--Erics IPB Game Mod---------------------------------
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 03:58:27 PM
There are a few more differences G6, however Paulie has got it working so details can be found later.

(OK now you corrected it)

He will be quite happy now, I believe  ;)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 03:59:08 PM
All done, thanks peeps.

Now i just have to figure out how to get you registered G6 lmao. I haven`t done this for a while.
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 04:01:28 PM
Paulie are you sure you had not changed index.php before the security update upload?

It' s important to know, so far those hacks did only redirection.
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 04:01:51 PM
Admin/members/ and in the bar you have activation ;)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:03:01 PM
No, i uploaded the index.php then the two patches.
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:04:24 PM
Quote from: G6 on April 29, 2006, 04:01:51 PM
Admin/members/ and in the bar you have activation ;)

That`s it lol, i can never remember that one. You`re in, mail sent etc.
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 04:05:08 PM
Thank you paulie :)
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 04:06:49 PM
I see that you dont have the shoutbox up and running Paulie ?
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:07:00 PM
No worries, maybe i can get to try out some Swedish recipes ;)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:07:31 PM
Quote from: G6 on April 29, 2006, 04:06:49 PM
I see that you dont have the shoutbox up and running Paulie ?

Lmao i got scared and turned it off
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:08:30 PM
On now
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 04:11:08 PM
You can turn it on now Paulie if you applied the patch.

You will see the redirection hack with tags stripped.

You will probably see who sent it.
Title: Re: Hacked/Defaced
Post by: G6Cad on April 29, 2006, 04:16:56 PM
I was just wondering if you havent had that going on your site, how did they manage to hack it  ???

But if you turned it off now that explain it i guess  :)
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:18:15 PM
Lol yeah i had it up and when i actually got in a cleared it i could see the redirect, so the first thing i did was turn it off.
Title: Re: Hacked/Defaced
Post by: agridoc on April 29, 2006, 04:21:17 PM
Paulie I saw from the message of G6 that members need activation by the administrator, did you allow guests shout?
Title: Re: Hacked/Defaced
Post by: Paulie on April 29, 2006, 04:27:40 PM
Quote from: agridoc on April 29, 2006, 04:21:17 PM
Paulie I saw from the message of G6 that members need activation by the administrator, did you allow guests shout?

Yeah i guess i should turn that off too eh.
Title: Re: Hacked/Defaced
Post by: Blue Steel on April 30, 2006, 05:06:31 AM
hmmm... so turn off shoutbox as its a security risk ???

Why do ppl have to disrupt everything just because they can. There is nothing safe anywhere in the world anymore. A world where Trust and ignorance gets you into so much trouble. and all the others do is laugh that they've caused aso much Havoc they don't care so long as they are having a good time.. in our case its the Cyber Vandals thats the problem.. not the ppl who hack systems and sites for a living.. just kids out for a good time, who read in the internet or were told by a friend how to disrupt particular web site constructs. and its the same no matter what you use. if you can build it they can break it..

Moral: Always Keep Backups and even Backups of your Backups


Title: Re: Hacked/Defaced
Post by: Wolfenrook on April 30, 2006, 11:02:27 AM
Bluesteel Bloc has fixed the shoutbox vulnerability already, you can get the updates from this thread (http://www.tinyportal.net/smf/index.php?topic=4440.0).  Also if you are still worried then just make sure that you do not have your permissions set to allow guests to shout.

Wolfenrook.
Title: Re: Hacked/Defaced
Post by: Paulie on May 01, 2006, 10:51:34 AM
I did have backups, but they were on my hdd that got fried. But that`s another story ;)
Title: Re: Hacked/Defaced
Post by: akulion on May 01, 2006, 02:56:40 PM
oh my im so sorry for u

I hope everything works out for u!

Title: Re: Hacked/Defaced
Post by: Paulie on May 01, 2006, 07:08:11 PM
Thanks, yeah i think i`m all back to normal (or a normal as i can be ;)). Couple of things to get sorted, but other than that.
Title: Re: Hacked/Defaced
Post by: akulion on May 01, 2006, 11:11:55 PM
yea i signed up :D hehe
Title: Re: Hacked/Defaced
Post by: Paulie on May 02, 2006, 12:02:16 AM
Cool, have fun ;)