TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
  • Total Members: 3,966
  • Latest: safir45
Stats
  • Total Posts: 195,993
  • Total Topics: 21,324
  • Online today: 388
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 0
  • Guests: 350
  • Total: 350

TP Hacked -- v0.86 with Shoutbox Patch -- still hacked

Started by BobbyKashyap, July 04, 2006, 12:39:30 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Maya

 :(This is a recurring event it would seem to be effecting quite a few. I too was hacked by turkish hackers a few weeks back. I don't run a shoutbox so I know it wasn't that

Just when I thought all was lost..I did a bit of investing through Cpanel.

I went in to the index.php ( as well as all the other pages) and they only messed with index.php. ( this is where hacked by blah blah...)
I went to a test site I have for trying new mods, scripts, etc.

copied the whole index.php and pasted it on to the hacked and voila! all was fixed.

while in Cpanel I noticed that I had left my permissions at 777 on settings.php ( as well as a few others that I can't recall darn it!), don't know if that had anything to do with it, but I haven't had  problems since...

Jump1979man

I have been getting A LOT of those hacker types trying to register on my site lately.....you can tell by the email they use.....*@gawab.com or *@gawab.ru

most use those but some dont.....

they dont ever actually confirm their email to register and they apparently cant hack the shoutbox anymore due to security fixes....

so I have just been deleting these accounts when I see them.

IchBin

Quote from: Mrs G6 on September 06, 2006, 11:05:09 PM
If it was through the server not even TP V.095 would have helped you, and keep your index,php file tight on the permission, i would have mailed my host and really asked about their security  >:(
Thats exactly what anyone should do is contact their host.

RoarinRow

Quote from: IchBinâââ,¬Å¾Ã,¢ on September 07, 2006, 02:56:29 AM
Quote from: Mrs G6 on September 06, 2006, 11:05:09 PM
If it was through the server not even TP V.095 would have helped you, and keep your index,php file tight on the permission, i would have mailed my host and really asked about their security  >:(
Thats exactly what anyone should do is contact their host.

My host was clueless. 

SMF 2.0 RC3
TP 1.0 beta 5-1
Wordpress 3.0

Jpg

Do a whois lookup on the website. You'll get all the owners private information and everything you need to sue em or get their website...well you know.

bloc

Quote from: RoarinRow on September 07, 2006, 03:15:08 AM
Quote from: IchBinâââ,¬Å¾Ã,¢ on September 07, 2006, 02:56:29 AM
Quote from: Mrs G6 on September 06, 2006, 11:05:09 PM
If it was through the server not even TP V.095 would have helped you, and keep your index,php file tight on the permission, i would have mailed my host and really asked about their security  >:(
Thats exactly what anyone should do is contact their host.

My host was clueless. 
Do you run just SMF+TP? Any other scripts..?

RoarinRow

Quote from: Bloc on September 07, 2006, 06:43:00 AM
Quote from: RoarinRow on September 07, 2006, 03:15:08 AM
Quote from: IchBinâââ,¬Å¾Ã,¢ on September 07, 2006, 02:56:29 AM
Quote from: Mrs G6 on September 06, 2006, 11:05:09 PM
If it was through the server not even TP V.095 would have helped you, and keep your index,php file tight on the permission, i would have mailed my host and really asked about their security  >:(
Thats exactly what anyone should do is contact their host.

My host was clueless. 
Do you run just SMF+TP? Any other scripts..?

Just SMF + TP, but I also have Coppermine Photo Gallery and FlashChat.

What should my index.php by chom'd too?

SMF 2.0 RC3
TP 1.0 beta 5-1
Wordpress 3.0

IchBin

I think to should probably be safe with 755 which makes it only writeable by the owner.

Svaha

I've chmodded my index.php to 444 (only readable) as I do for settings.php

I've read somewhere else that sometimes hackers execute a php script in directories where you keep your image files, this can be prevented by placing and htaccess file in these directories

Svaha

This was posted by bandit-x on the xoops forum :

for my uploads directory i got something like
:
Quote:
Order Deny,Allow
Deny from all
<FilesMatch "\.(gif|jpe?g|png)$">
Allow from all
</FilesMatch>

only the .gif .jpg .jpeg and .png image files are web accessible in that directory. the rest of the files in that directory get a 404

This website is proudly hosted on Crocweb Cloud Website Hosting.