TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
Stats
  • Total Posts: 196,004
  • Total Topics: 21,330
  • Online today: 219
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 1
  • Guests: 97
  • Total: 98
  • @rjen

Website Hacked/Defaced

Started by yrral, March 23, 2007, 02:05:33 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

yrral

Help guys... for two nights my website/forum has been defaced by the so-called Hackerfreeze & Tetikci. :idiot2:

I tried to restore the index.php/index.html file that they uploaded first night but on the second might they did again... this time I restored the said file and also upgraded to TP v.0.9.8 and SMF 1.1.2... I even disabled shoutbox for now as I've read during my search here that they can also use shoutbox to inject some rouge file or something.

They even put their website on: TurkHackBirligi.Org

My website is here: http://www.atimonan-quezon.com/www/index.php

All of the website in atimonan-quezon.com are placed in a folder and become a sub-domain... all other websites are working fine except for the website on www folder which is the only website in the domain that runs TP and SMF.

Porky

#1
due you have other mods installed, because I serious doubt they did through SMF or TP. the shoutbox has been fixed.

yrral

#2
Thanks for the quick reply...

I've got the following MODS installed: (cut-n-paste :P)

Mod Name Version 
1. Users Online Today Mod 1.4.0  [ Apply Mod ] [ List Files ] [ Delete ] 
2. Ad Managment 2.0  [ List Files ] [ Delete ] 
3. Admin Notepad 1.0  [ List Files ] [ Delete ] 
4. Enhanced Quick Reply TBA   [ Uninstall ] [ List Files ] [ Delete ] 
5. SMF Gallery Lite 1.6.9  [ List Files ] [ Delete ] 
6. Member Color Link 1.8.7  [ List Files ] [ Delete ] 
7. TinyPortal 0.983   [ Uninstall ] [ List Files ] [ Delete ] 
8. Reason For Editing Mod 1.14  [ Apply Mod ] [ List Files ] [ Delete ] 
9. Merge Double Posts 1.0.6  [ List Files ] [ Delete ] 

Yeah... I'm pretty sure that it came either from SMF or TP (I'm not blaming you guys... it's the best) because it didn't happen to other website in the subdomain.

IchBin

If you're on a shared host its more than likely not getting hacked because of you. It could be another customer using an unsafe script that causes havoc on all the sites including yours. Are you running any other scripts? Until you have talked with your host I would just change your files so that they aren't writable.

yrral

Boss, I'm the only administrator for this domain (CPANEL)... all the other website on a sub-domain are all maintained by me.

http://www.atimonan-quezon.com/acsc <== Pure HTML
http://www.atimonan-quezon.com/kabalikat <== Html and some PhP for Photo Gallery and EMail Form which I've been using since day one.

http://www.atimonan-quezon.com/ redirect to http://www.atimonan-quezon.com/www which is the main website... I just put it on that folder so everything is properly organized from the root folder (public_html)

G6Cad

Seen this on SMF forums, and they have all lead to the hosts server script.
Wrong settings allowed the hackers to get in through a backdoor and changed the index.php file (or rather replaced it)
Si if you are the only one on the server, and the server is owned by you, you have to find the backdoor they got in and close it.

Try a search on SMF forums to, if i remember correct there were a post there frrom a host admin that explained how they got in and how he closed the backdoor.


G6Cad

No, it's not the correct thread ;)

IchBin

Quote from: yrral on March 23, 2007, 03:49:04 AM
Boss, I'm the only administrator for this domain (CPANEL)... all the other website on a sub-domain are all maintained by me.

http://www.atimonan-quezon.com/acsc <== Pure HTML
http://www.atimonan-quezon.com/kabalikat <== Html and some PhP for Photo Gallery and EMail Form which I've been using since day one.

http://www.atimonan-quezon.com/ redirect to http://www.atimonan-quezon.com/www which is the main website... I just put it on that folder so everything is properly organized from the root folder (public_html)
So are you the owner of the server? Are you the only site hosted on this server? Is this a dedicated server? If not, then there are other people being hosted on the server besides you.

bloc

Apart from the other things asked here, I would simply try running something else for a while, to see if it still gets defaced without any trace of SMF/TP on the server.

This website is proudly hosted on Crocweb Cloud Website Hosting.