TinyPortal
Development => Support => Topic started by: itsacoaster on April 10, 2010, 07:10:14 AM
Hello TP folks,
I found out that it was possible my website was hacked. A spamming PHP script found itself in my tp-images folder on my website. I believe the file was named _system32.php. I am just posting to see if there have been any other reports like this--or if it's only a coincidence that the bad script was in the tp-images folder.
Thanks everyone.
Edit: there were actually four files, their names are below
index.php
phpsh.php
r57shell.php
_system32.php
One More Edit: Doh, I forgot to tell you the version. TP 0.98 and SMF 1.1.11
never seen a report of that kind for the verision you use, mor likly it's something thats been uploaded through your downloadmodule at some time.
My Gmail / account / contacts....... was indeed hacked ... so i dunno?
Quote from: G6 on April 10, 2010, 07:36:28 PM
never seen a report of that kind for the verision you use, mor likly it's something thats been uploaded through your downloadmodule at some time.
Thanks for the reply. I think it's unlikely that someone uploaded it, since nothing has been uploaded lately and the problem appeared in the last month. There was a good likelihood that it didn't have anything to do with TP at all. I'll post back if I find out more.
You should be able to have the host look to see when and how those scripts were put there. Let us know what you find out.
if you've allowed people to upload .php files then your a nut. by default its not one of the default file types to accept.