TinyPortal

Development => Support => Topic started by: itsacoaster on April 10, 2010, 07:10:14 AM

Title: Spam Abuse
Post by: itsacoaster on April 10, 2010, 07:10:14 AM
Hello TP folks,

I found out that it was possible my website was hacked.  A spamming PHP script found itself in my tp-images folder on my website.  I believe the file was named _system32.php.  I am just posting to see if there have been any other reports like this--or if it's only a coincidence that the bad script was in the tp-images folder.

Thanks everyone.

Edit:  there were actually four files, their names are below

index.php
phpsh.php
r57shell.php
_system32.php

One More Edit:  Doh, I forgot to tell you the version.  TP 0.98 and SMF 1.1.11
Title: Re: Spam Abuse
Post by: G6Cad on April 10, 2010, 07:36:28 PM
never seen a report of that  kind for the verision you use, mor likly it's something thats been uploaded through your downloadmodule at some time.
Title: Re: Spam Abuse
Post by: Crip on April 10, 2010, 08:24:25 PM
My Gmail / account / contacts....... was indeed hacked ... so i dunno?
Title: Re: Spam Abuse
Post by: itsacoaster on April 10, 2010, 10:05:27 PM
Quote from: G6 on April 10, 2010, 07:36:28 PM
never seen a report of that  kind for the verision you use, mor likly it's something thats been uploaded through your downloadmodule at some time.
Thanks for the reply.  I think it's unlikely that someone uploaded it, since nothing has been uploaded lately and the problem appeared in the last month.  There was a good likelihood that it didn't have anything to do with TP at all.  I'll post back if I find out more.
Title: Re: Spam Abuse
Post by: IchBin on April 11, 2010, 01:17:53 AM
You should be able to have the host look to see when and how those scripts were put there. Let us know what you find out.
Title: Re: Spam Abuse
Post by: Blue Steel on April 11, 2010, 02:29:06 AM
if you've allowed people to upload .php files then your a nut. by default its not one of the default file types to accept.