Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security ⇒ [solved] Has My Site Been Hacked?


[solved] Has My Site Been Hacked?
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Security

View previous topic :: View next topic  
Author Message
wendys_whimseys
Newbie
Newbie

Offline Offline
Joined: Sep 15, 2009
Posts: 3
Location: Pacific Northwest
PostPosted: Tue Sep 15, 2009 6:12 pm
Post subject: [solved] Has My Site Been Hacked?

Hello Everyone,

I'm new to the Forum... because my installation and use of Dragonfly CMS went so smoothly, that I haven't had any real issues... until now... Shocked

On August 14th, when I visited my website... I received a Trojan Alert message from Windows Live OneCare. I've attached a screenshot of the alert, below.

Now I'm wondering if my site's been hacked and a Trojan has been embedded? I've looked through the source code and couldn't find any unusual scripts... but I'm not even sure where I should be looking? Confused

So I guess these are my questions:

1 - Is it possible for someone to hack Dragonfly CMS and embed a Trojan in my website?

2 - If so... is there any way to find the area that was hacked and fix it?

3 - Are there any security measures I can take to keep my site from being hacked again?

I'm going to provide a link to my site... but you should only click on the link, if you have security software that will detect and remove a Trojan (as I do).

If anyone could take a look at my site and let me know what they can find, I'd appreciate your help:

aceoaddix.com/

Thanks so much! Very Happy


wendys_whimseys's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian OS / Apache ? / MySQL 5.0.83 / PHP 5.2.12 / Dragonfly CMS 9.2.1
Back to top
View user's profile Visit poster's website
Dizfunkshunal
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Mar 23, 2006
Posts: 2064

PostPosted: Tue Sep 15, 2009 10:57 pm
Post subject: Re: Has My Site Been Hacked?

1. Yes it is possable but highly unlikely. If you did get hacked 9 times out of 10 they found a weak spot on your server.
2. Search your logs all of them. For now tho i would recommend uploading a clean copy of all your files over writing the current ones.
3. Yes, but first need to find out what the problem is to figure out what needs to be done to secure it.


I dont see a screenshot?

_________________
Diz Web Design Status: Open (Use of resources requires registration.)

Dizfunkshunal's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Multiple Setups
Back to top
View user's profile Send e-mail Visit poster's website Yahoo Messenger
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Wed Sep 16, 2009 7:57 am
Post subject: Re: Has My Site Been Hacked?

"On August 14th" and you register/report now ... take your time mate Wink

Anyway, unless you run your own modules or 3rd party untrusted modules, the only way to hack your website is from inside your server.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
wendys_whimseys
Newbie
Newbie

Offline Offline
Joined: Sep 15, 2009
Posts: 3
Location: Pacific Northwest
PostPosted: Wed Sep 16, 2009 10:30 am
Post subject: Re: Has My Site Been Hacked?

I attached a JPEG of the screenshot, but the attachment isn't showing in my first post... Confused

So here it is again:



However... I have a Co-Admin, who has more experience with DF... and she seems to have fixed the issue. Very Happy

When I find out what happened and how she fixed it, I'll share the info here and see what you guys think.

Thanks for your help! Very Happy


wendys_whimseys's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian OS / Apache ? / MySQL 5.0.83 / PHP 5.2.12 / Dragonfly CMS 9.2.1
Back to top
View user's profile Visit poster's website
wendys_whimseys
Newbie
Newbie

Offline Offline
Joined: Sep 15, 2009
Posts: 3
Location: Pacific Northwest
PostPosted: Thu Sep 17, 2009 8:14 pm
Post subject: Re: Has My Site Been Hacked?

OK... looks like the free plugboard that I was using from PlugMe.net was generating the Trojan alert.

I've been using that service for almost a year, with no problems... they must have just changed the script or maybe it's a new glitch with OneCare... Confused

Either way... I switched to a plug script from Plugboard.org and the Trojan warnings are gone.

Thanks for your help! Very Happy

_________________
~ Wendy

wendys_whimseys's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian OS / Apache ? / MySQL 5.0.83 / PHP 5.2.12 / Dragonfly CMS 9.2.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.
· Removed index.php depency.
· v9 fixed menu hoverings on touch screens.
· Fixed menu hoverings on touch screens.
· Fixed empty $Module object

devamı...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy