Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ hacked and wiped out :: Archived


hacked and wiped out :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Fri Jan 06, 2006 6:49 am
Post subject: hacked and wiped out

Hello. I have been running phpNuke for several years now. For the past 3 days we have been having very big issues with hacking. Our database has been wiped again and again and scripts inserted redirecting to the likely culprits website.

Today we made the switch and started off clean. Changed database passwords, names, and erased every file off the directory and installed a fresh version of the latest Dragonfly.

After we got it configured to a point acceptable enough to launch it wasn't even 5 minutes later and the database had been wiped again.


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Fri Jan 06, 2006 6:59 am
Post subject: Re: hacked and wiped out

Depends on a wide variety of issues, a few of which are,

1. an inside job?
2. has any unusual file been added to your server, below public_html level?
3. did you change your server password?
4. how many FTP accounts have access to your site and did you change them?
5. was the Dragonfly install a bare install without phpnuke modules?

We are not aware of any Dragonfly vulnerabilities, other than what comes from shared hosting or insecure third party modules.


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Fri Jan 06, 2006 3:22 pm
Post subject: Re: hacked and wiped out

Thanks for the reply. We are totally boggled by it.

I am the only person with ftp or mysql access for the account. Before installing Dragonfly I erased all files from public_html and checked and erased many outside as well.

Dragonfly was a fresh install on a new database under a new name and password.


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Fri Jan 06, 2006 3:33 pm
Post subject: Re: hacked and wiped out

Did you also change your FTP and cPanel login account password ?
Did the 'root' login user also change his password ?


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
djdevon3
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 05, 2004
Posts: 4363

PostPosted: Fri Jan 06, 2006 3:58 pm
Post subject: Re: hacked and wiped out

they could have also gotten in because your webhost runs insecure third party addons or even an insecure install of apache, etc... I would look elsewhere for the hole now such as contacting your webhost and tell them whats going on. I'm sure they'll be quick to blame phpnuke and dragonfly but if their heads are screwed on straight they'll look extremely hard at themselves.


djdevon3's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33/4.4/4.3.11
Back to top
View user's profile Visit poster's website Photo Gallery
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Fri Jan 06, 2006 4:43 pm
Post subject: Re: hacked and wiped out

Thanks. I have been in contact with my webhost from the very start and he was the one who recommened I switch to Dragonfly Smile and I plan to stick with it once this is fixed.

We are working closely to find the hole as well as trying to contact others since we are not the only ones to be attacked by this hacker.


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
dormouse
Newbie
Newbie

Offline Offline
Joined: Aug 31, 2005
Posts: 37

PostPosted: Fri Jan 06, 2006 4:53 pm
Post subject: Re: hacked and wiped out

LoneWolf367 wrote:
LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / CPG-Nuke)
Linux/1.33/4.0.22/4.3.1/phpNuke 7.6

Do you really mean php 4.3.1?

I must say that the speed makes it sound like a server hack rather than a dragonfly hack since you had not had dragonfly up before & no problems have been identified elsewhere.


dormouse's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.39/4.1.22/4.4.7/9.2.0
Back to top
View user's profile Visit poster's website
Wide
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 07, 2004
Posts: 294
Location: Playa Del Rey, CA
PostPosted: Fri Jan 06, 2006 5:14 pm
Post subject: Re: hacked and wiped out

Looks like they have you covered.
If you do have ssh tot he server I would check for a rootkit (I'm sure your host has this well covered).
Logs logs logs tell stories.

Another thing that comes to mind is a "man in the middle attack" are you running over a wireless connection. Been getting a lot of these lately with the "tutorials" going around.

Don't forget to go over possibilitys on your end, key loggers etc.


Wide's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian/Apache2/MySQL 4.1.15-Debian/PHP4 4.4.2-1build1/9.1.1
Back to top
View user's profile Visit poster's website
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Fri Jan 06, 2006 5:42 pm
Post subject: Re: hacked and wiped out

I will have my webhost comb through the system to make sure nothing has been planted... since that'd be very bad considering I host more than just my own site.

I am not operating on a wireless connection. And I've also looked over processes at my end just to be safe. I'm running MacOS 10.4.

I just updated my server specs.


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
Wide
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Aug 07, 2004
Posts: 294
Location: Playa Del Rey, CA
PostPosted: Fri Jan 06, 2006 7:36 pm
Post subject: Re: hacked and wiped out

Cool, if worst comes to worst & they can't find the cause or you are not satisfied with their explanation you may want to ask to have your account moved to another server.


Good luck!! Smile

Look foward to checking out your site, sounds right up my ally


Wide's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian/Apache2/MySQL 4.1.15-Debian/PHP4 4.4.2-1build1/9.1.1
Back to top
View user's profile Visit poster's website
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Sat Jan 07, 2006 10:36 pm
Post subject: Re: hacked and wiped out

Ok. We increased logging detail to try and find out what is going on. He knows our password. No guessing is visible and seems to have his methods very automated. Our config file is outside of the public_html path. We've changed all our passwords at least once a day since the hacking began.

He is getting our password and going right in, only takes a matter of minutes. In our apache log a XSS attack showed up. He is also going through a proxy.

Is there any way to protect our config file?


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Sat Jan 07, 2006 10:55 pm
Post subject: Re: hacked and wiped out

what type of XSS attacks ?

config.php is NOT the issue, you may keep it in public_html since that file is well protected and only accessible thru the CMS itself or a different script.

If you are using Downloads Pro beta software be shure you have the latest which has a security exploit fixed.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Sat Jan 07, 2006 11:30 pm
Post subject: Re: hacked and wiped out

Ok, I have applied those patches.

My webhost isn't really too firmiliar with XSS and says he hasnt had much experience in dealing with them.

I have applied the patche for Downloads Pro.

My database is back up. Our hacker is watching us and has attacked 4 times so far today.


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
sarah
Debugger
Debugger

Offline Offline
Joined: Mar 25, 2005
Posts: 2130

PostPosted: Sat Jan 07, 2006 11:49 pm
Post subject: Re: hacked and wiped out

This might be a stupid question, but are you totally sure .htaccess is getting put on the server when you upload your files?

Also in addition to changing the cpanel, ftp and database passwords are you changing the passwords for dragonfly admins?

_________________
Diagon Alley - Top Design

sarah's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.37/4.1.21-standard/4.4.4/9.1.1
Back to top
View user's profile Send e-mail Visit poster's website
LoneWolf367
Newbie
Newbie

Offline Offline
Joined: Mar 06, 2005
Posts: 8

PostPosted: Sat Jan 07, 2006 11:54 pm
Post subject: Re: hacked and wiped out

Yes .htaccess is there. I have renamed admin.php and I just changed my password.

Also, is there anyway to take out the database features from the admin panel temporarily?


LoneWolf367's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD 5.4/Acpache 1.3.33/PHP 5.1.1/MySQL 4.13/CPG Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

もっと読む

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy