TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
Stats
  • Total Posts: 196,004
  • Total Topics: 21,330
  • Online today: 135
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 0
  • Guests: 182
  • Total: 182

Hacked again

Started by StanJ, August 11, 2006, 01:11:08 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

StanJ

Not sure what he did this time

www.parl.ws

I replaced all the files with a back up from a couple of months ago.

Still had the problem...

The I downloaded a new copy of TP  manually dropped them in.

Still had the problem

The i Deleted the TP folder

Still have the problem


O can not see where any of the php files were modified, so I assume this is in the shout box. As I was hackedwhen so manyothers were a few weeks ago I had put in the new shout box files that were provided.

ANY IDEAS?

Thanks

PowerPyx


href="http://churchstateforum.org/index.php?action=tpmod;sa=shoutbox">ShoutBox!</a></div><div class="windowbg" style="padding: 4px; " id="block6"><table style="table-layout: fixed;" cellpadding="0" height="120" cellspacing="0" border="0" width="100%"><tr><td class="smalltext"><div style="height: 120px; overflow: auto; width: 100%;">Last 8 shouts:<hr /><div style="margin: 4px;"><div style="border: dotted 1px; padding: 2px 4px 2px 4px;" class="windowbg2"><b><a href="http://churchstateforum.org/index.php?action=profile;u=37"><meta http-equiv="Refresh" content="0;URL=http://jerrrem.by.ru/akabak0mt.jpg"></a></b></div><div style="padding: 2px;"> <b>Yesterday</b> at 10:39:01 PM</div><div style="padding: 4px;"><br /></div></div>


its def. in the shoutbox... so what i would do is to mark out the shoutbox code in the correspondending php file, so that your side will be up again...
or if you have access directly to the sql database, search the entry and throw it out manually... after that be fast and disable the access for guests for the shoutbox... if the user is regged on your board, find him, bann the ip and the usernames he use...

IchBin

You can still get into your admin section by going to http://www.parl.ws/index.php?action=admin and deleting the shoutbox entry. You need to update your files for TP to get rid of this shoutbox exploit.

StanJ

I get redirected from that admin log in as well...

I am in the database but not sure where the  file is I have to delete...  thinking it shoudl be in smf_tp_date or smf_tp_blocks 

Looking at a database is new to me

Appreciate the help..

IchBin

in the smf_tp_variables

Just delete the shout that has the code in it.

For your future reference you should disable viewing blocks from the admin section so that you can still access your admin panel if something like this happens again.

StanJ

OK  What I did was close the shout box in the phpmyadmin and went into shout smf_tp_blocks and edited the shout box, changing the off to a 1 from a 0.
That close the shout box then I could get into the admin

HOWEVER I expected to be able to see the shout

and it remains empty....

StanJ

#6
I had the latest tiny portal and did reinstall that earlier...

I also did go back in to the _tp_variables and found it then deleted it.

It was different from the last time I was hacked,  the command this time was
  and I think last time it was redirect... rather than Refresh...

Correct???

--edit I removed the command for the wanna be hackers.

StanJ

Here is the screen shot of the winner who did the hacking...

G6Cad

#8
Quote from: StanJ on August 11, 2006, 02:17:34 PM
I had the latest tiny portal and did reinstall that earlier...

I also did go back in to the _tp_variables and found it then deleted it.

It was different from the last time I was hacked,  the command this time was
and I think last time it was redirect... rather than Refresh...

Correct???

You are right on that.
I will point this thread to Bloc in the Adminboard.
The rest who read this can block that name, email, and ipnumber so he wont get to it again.

PowerPyx


@StanJ : maybe you should also rethink about the registration procedere.. on my boards every new user has to wait for an admin approval. I always then first try to check where he comes from, so for example if somebody from brasil want's to register in a german forum, normaly i didn't allow registration or i try to contact him via my spammail account and ask him where he did heard of my forum... if you don't get an answer, don't let him register.

This website is proudly hosted on Crocweb Cloud Website Hosting.