Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ Miscellaneous ⇒ Server Chat ⇒ gumblar.cn Malware attact on my site !


gumblar.cn Malware attact on my site !
Talk about good (DedicatedNOW) and bad (AdventureHost) hosts, or any other question about servers and hosting, but no advertising or pricing in any form.
Go to page 1, 2  Next
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Server Chat

View previous topic :: View next topic  
Author Message
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Wed May 06, 2009 12:12 pm
Post subject: gumblar.cn Malware attact on my site !

Hi all
I did a search for "gumblar.cn" .. it seems no one else has got it yet .. but according to a Google search this tosser at "gumblar.cn" has been very active over the last 3 months.

Apparently he "brute forces" his way into your ftp account .. downloads files and re-uploads them with some sort of java script code. (no idea what he expects it to do .. but it does stop my site from working !)

Looking in my ftp window .. I could see many files that were uploaded on May 5th between midnight and 6 a.m (what a tosser!.. what a way to spend your time !)

My site was "riddled" with new uploaded files .. especially the includes directory. There was also a new file called "image.php" in the image directory .. I deleted that.

So .. I re-uploaded my entire sites backup on my pc (with the exception of "includes/config.php" .. That one I had to download .. remove the malware java script and re-upload it.

OK .. I checked and doubled checked that everything was squeaky clean again and tried to load my site.

NOW .. the problem .. I get the following error message ..

Fatal error: Class 'sql_db' not found in /****/****/teachermark.6te.net/includes/db/db.php on line 377

(I replaced some of the address with asterisks)

That line refers to my database name/password etc.

Does DF write anything to that file during installation? Did I overwrite anything by re-uploading a fresh copy of "db.php"?

Thanks in advance

Shocked


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Wed May 06, 2009 12:17 pm
Post subject: Re: gumblar.cn Malware attact on my site !

Sorry for the extra post .. no edit function for me yet! Here's my site address teachermark.6te.net


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
greenday2k
Forum Admin
Forum Admin

Offline Offline
Joined: Aug 11, 2005
Posts: 489
Location: CO
PostPosted: Thu May 07, 2009 2:41 am
Post subject: Re: gumblar.cn Malware attact on my site !

Code::
Parse error: syntax error, unexpected '<' in /home/vhosts/teachermark.6te.net/index.php on line 139

_________________
www.greenday2k.net


greenday2k's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website MSN Messenger Yahoo Messenger
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Thu May 07, 2009 4:41 am
Post subject: Re: gumblar.cn Malware attact on my site !

I moved this to the Server Chat area as it's highly unlikely to be a DF matter.

You'll need to Google this issue and take it up with your (free) host.

Regrettably, you get what you pay for Sad


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Thu May 07, 2009 9:22 am
Post subject: Re: gumblar.cn Malware attact on my site !

greenday2k wrote:
Code::
Parse error: syntax error, unexpected '<' in /home/vhosts/teachermark.6te.net/index.php on line 139

I just got home from work. The index.php file has been attacked again ! This time at 1pm today.That's what causing the syntax error. Heres the code that was added to the end of my index.php file. I know it won't help .. but I'll just post it for curiosities sake.

{script removed - DF policy}

So ..I re-uploaded a fresh copy of index.php .. and now I am back to the aforementioned error again .. namely ..
Quote::
Fatal error: Class 'sql_db' not found in /home/vhosts/teachermark.6te.net/includes/db/db.php on line 377


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Thu May 07, 2009 9:25 am
Post subject: Re: gumblar.cn Malware attact on my site !

Phoenix wrote:
I moved this to the Server Chat area as it's highly unlikely to be a DF matter.

You'll need to Google this issue and take it up with your (free) host.

Regrettably, you get what you pay for Sad

So no help for people on free hosts from DF? Thanks.Looks like it time to change hosts and CMS. Shocked


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Thu May 07, 2009 9:36 am
Post subject: Re: gumblar.cn Malware attact on my site !

Change CMS by all means but don't expect any difference in a free shared host environment, especially one that appears to be compromised. No CMS will survive an attack through the server itself and you did indicate your FTP was compromised - we cannot stop that.

I sincerely meant "you get what you pay for" - you will get zero help from a zero cost host and I believe your host, and perhaps even one of more of the other free clients, to be the source of your problem.

It is not possible for us to solve what appears to be a hosting issue - have you even discussed it with them?


Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eestlane
I18N / L10N Lead Dev
I18N / L10N Lead Dev

Offline Offline
Joined: Apr 06, 2005
Posts: 1404
Location: Estonia
PostPosted: Thu May 07, 2009 9:50 am
Post subject: Re: gumblar.cn Malware attact on my site !

I had the same problem on pretty lousy server host (it still runs php 4 and also support is non existant). Twice.

Which seemed to help was changing the folder permissions to 755 instead of 777 and file permissions to 644.

Also, change all passwords (cpanel, ftp, mysql user).

To fix the site itself, you have to reupload the files probably.


Eestlane's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.0.63/5.0.67/5.2.8/9.2.1
Back to top
View user's profile Send e-mail Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Thu May 07, 2009 9:53 am
Post subject: Re: gumblar.cn Malware attact on my site !

Before I posted this query .. I created a subdomain and did a fresh install of Df .. works OK.

As for my original site .. I re-uploaded my complete uninfected backup site plus the config.php with the above malware script removed and get the "Fatal error: Class 'sql_db' not found in /home/vhosts/teachermark.6te.net/includes/db/db.php on line 377" error.That looks like a DF problem to me. But if no one want to help .. then fair enough .. like you said .. "you get what you pay for" .. and DF is free. I can wear that. No complaints.

Thanks Smile

_________________
Ajarnmark

keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
Eestlane
I18N / L10N Lead Dev
I18N / L10N Lead Dev

Offline Offline
Joined: Apr 06, 2005
Posts: 1404
Location: Estonia
PostPosted: Thu May 07, 2009 9:56 am
Post subject: Re: gumblar.cn Malware attact on my site !

Maybe you should try using the files from the original archive as maybe the backup has some broken files in it.

dragonflycms.org/Downl...ils/id=28/


Eestlane's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.0.63/5.0.67/5.2.8/9.2.1
Back to top
View user's profile Send e-mail Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Thu May 07, 2009 9:59 am
Post subject: Re: gumblar.cn Malware attact on my site !

The backup is the original archive .. with additional modules and blocks etc added. I make the changes on the backup on my pc first .. then upload.None of it has been downloaded.. except for when I originally downloaded the zipped original of course.... (with the exception of Album pics and user avatars


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
rlgura
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: Mar 27, 2006
Posts: 1146
Location: Cleveland, OH USA
PostPosted: Thu May 07, 2009 5:29 pm
Post subject: Re: gumblar.cn Malware attact on my site !

back to the original error again - I think your host server is compromised.

Anyway, the sql_db class is defined by the db abstraction layer which is defined in includes/config.php.

make sure your config.php is uncompromised and has the following entry:
define('DB_TYPE', 'mysql');
this will include the includes/db/mysql.php file which defines that class

_________________
Admin - Great Lakes Web Designs
Theme Designer - WebSite Guru Designs
Site Admin - Families with Food Allergies

rlgura's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.6.27-grsec/Apache 2.2.11/MySQL 5.0.67-community-log/PHP 5.2.8/DF 9.2.1
Back to top
View user's profile Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Thu May 07, 2009 10:28 pm
Post subject: Re: gumblar.cn Malware attact on my site !

Would someone be able to post a copy of a normal config.php (df 9.2.1) file here so I can compare it with mine? Just remove your db name /password of course!
Thanks

_________________
Ajarnmark

keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
rlgura
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: Mar 27, 2006
Posts: 1146
Location: Cleveland, OH USA
PostPosted: Fri May 08, 2009 9:26 pm
Post subject: Re: gumblar.cn Malware attact on my site !

Code::
<?php
/*********************************************
  CPG Dragonfly CMS
  ********************************************
  Copyright (c) 2004 - 2007 by CPG-Nuke Dev Team
  http://dragonflycms.org

  Dragonfly is released under the terms and conditions
  of the GNU GPL version 2 or any later version

  $Source: /cvs/html/install/config.php,v $
  $Revision: 9.5 $
  $Author: nanocaiordo $
  $Date: 2007/04/23 10:43:36 $
**********************************************/
if (!defined('CPG_NUKE')) { exit; }

define('DB_TYPE', 'mysql');
define('DB_CHARSET', NULL); // NULL (is default), latin1, utf8, etc.
$dbhost = 'localhost';
$dbname = 'df';
$dbuname = 'user';
$dbpass = 'pass';
$prefix = 'cms';
$user_prefix = 'cms';

# -- $adminindex -----------------------------------------
# The filename of the admin index page I'd like to use for
# my site
#
# If you change this to something other than it's default
# value, you must also rename the file called 'admin.php'

# to the new value you assigned to this variable
#
# default: admin.php
# --------------------------------------------------------
$adminindex = 'admin.php';

# -- $mainindex ------------------------------------------
# The filename of the main index page I'd like to use for
# my site
#
# If you change this to something other than it's default
# value, you must also rename the file called 'index.php'
# to the new value you assigned to this variable
#
# default: index.php
# --------------------------------------------------------
$mainindex = 'index.php';

# -- admin demo mode -------------------------------------
# Alter the following value to activate the administrative
# system demonstration mode, enabling my users to browse
# my administration menu in a read-only environment
#
# true  = enabled
# false = disabled
#
# default: false
# --------------------------------------------------------
define('CPGN_DEMO', false);

# -- debug mode ------------------------------------------
# Alter the following value to activate debug mode, which
# will show debug messages to all users, instead of
# administrators
#
# Warning: Enabling debug mode is NOT recommended for
#          production websites
#
# true  = enabled
# false = disabled
#
# default: false
# --------------------------------------------------------
define('CPG_DEBUG', false);

# --- WARNING --------------------------
# Do not touch anything below this point
# unless you know what you're doing
# --------------------------------------

$CensorList = array('zak');
$DeniedUserNames = array('operator');
//session_save_path('/home/SOMETHING/tmp');

_________________
Admin - Great Lakes Web Designs
Theme Designer - WebSite Guru Designs
Site Admin - Families with Food Allergies

rlgura's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.6.27-grsec/Apache 2.2.11/MySQL 5.0.67-community-log/PHP 5.2.8/DF 9.2.1
Back to top
View user's profile Visit poster's website
keekwai
Nice poster
Nice poster

Offline Offline
Joined: Apr 01, 2008
Posts: 50
Location: Thailand
PostPosted: Sat May 09, 2009 12:56 am
Post subject: Re: gumblar.cn Malware attact on my site !

Thanks for that rigurra. It's identical to mine (except for the censor list) .. back to the drawing board.

I think I'll drop the database .. re-install DF .. if it's working I'll drop the new DB and upload the old one and see how that goes.


keekwai's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP/Apache 2.0/MySQL5.0.77/Dragonfly9.2.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Server Chat
Page 1 of 2
All times are GMT
Go to page 1, 2  Next



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

read more...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy