AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 04:25:25 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4765 Members
Latest Member: hunteryazmin
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  Mambo - Joomla  |  General Discussions  |  Topic: Hacked Site 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Hacked Site  (Read 2737 times)
drewser
Full Member
***
Offline Offline

Posts: 6


View Profile
Hacked Site
« on: January 20, 2006, 10:55:11 AM »

Thanks for the heads up on how to fix the hacking for Mambo, etc.

But I am somewhat confused.

How am I affected by Mambo,Joomla and Xoops, if neither myself or my site is using them?  How can I remove this from my site via Cpanel, since according to my list of installed applications, none of those 3 applications was installed, but yet my site was hacked anyway...


BTW, my site is

www.fbiyouth.webs4christ.com




Andrew
« Last Edit: January 20, 2006, 10:56:44 AM by drewser » Logged
Jennifer
Tech Volunteer
Full Member
******
Offline Offline

Posts: 18



View Profile
Re: Hacked Site
« Reply #1 on: January 21, 2006, 07:47:24 AM »

What application are you using and why do you think your site was hacked?

Jen
Logged
drewser
Full Member
***
Offline Offline

Posts: 6


View Profile
Re: Hacked Site
« Reply #2 on: January 23, 2006, 11:47:47 AM »

YaBBSe v1.5.5 (php Discussion Forum).

Is this a php hacking problem?  If so, How can I upgrade/patch the PHP server, being I am not a SysAdmin.

As for how do I know it was hacked?  I was emailed by a SysAdmin that it was hacked.  I was told to post my problem here in this discussion forum, as the site is a free site graciously hosted by alphaone.  I am merely trying to do my part and maintain security of what I run the site they host.  My question is realted to this thread...

http://www.alphaone-tech.com/smf/index.php/topic,758.0.html

Which is also related to this thread:

http://www.alphaone-tech.com/smf/index.php/topic,27.0.html



Either way, I need to better understand the security issues regarding the application on the site they host for me, as so far I have not found any patches/security updates for the application installed.


Perhaps what needs to occur is a new software needs to be installed (gasp, shudders at the thought), because according to this, YaBBSe is being put to rest as a project, meaning security updates may not be developed for the final released version.

http://www.yabbse.org/yse_history.html



According to this site, version 1.5.5 takes care of SQL injection vulnerabilities...
http://www.sans.org/newsletters/risk/vol3_3.php


Also, according to the decoded Base64 data in some new files found in one of the folders, I find these sites via google...
http://cutephp.com/forum/index.php?showtopic=13398
http://www.jaguarpc.com/forums/showthread.php?t=13305


I wonder if this vulnerability is realted to this one...
http://www.xatrix.org/article.php?s=2576

Or any one of three on this one page...
http://seclists.org/lists/bugtraq/2004/Mar/0001.html



Either way, it seems that something is rotten in Denmark.  Being a software developer myself, it only makes sense to either secure the application already installed, or to install a more secure application (which may intorduce brand new security issues altogether).

Maybe I will get a descent reply from a SysAdmin soon.  Thanks for your reply.
Logged
drewser
Full Member
***
Offline Offline

Posts: 6


View Profile
Re: Hacked Site
« Reply #3 on: January 23, 2006, 11:49:30 AM »

I also just noticed that this very supprt forum is running SMF, the recommended next level for YaBBse upgrade, since YaBBSe is no longer supported.
Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: Hacked Site
« Reply #4 on: January 23, 2006, 11:19:30 PM »

A lot has gone wrong in Denmark.

Two sites, (possibly more), have been seriously hacked by a hack that takes advantage of some of the security holes that are required to ALLOW most of the standard PHP apps to run!  These two sites have been identified as the starting culprits for the current wave of hacking attempts.

Our advise is to upgrade to SMF AND disable any uploding capabilities in SMF.
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
drewser
Full Member
***
Offline Offline

Posts: 6


View Profile
Re: Hacked Site
« Reply #5 on: January 24, 2006, 06:19:04 AM »

Thankyou for your reply.  I will be looking into upgrading to SMF asap.




Thanks!


Andrew
Logged
drewser
Full Member
***
Offline Offline

Posts: 6


View Profile
Re: Hacked Site
« Reply #6 on: January 24, 2006, 07:56:30 AM »

Ok, so it took about 2 hours to upgrade (I had to manually create the folders on the server because WS_FTP could not create the folders during the copy).

I did get an odd error the first run through the upgrade.php, but then I clicked refresh on the browser and everything continued to progress again.

Everything seems to be working fine now, other than my disk usage being pushed to the max with the new forum.  Looks like I will have to determine which forum style to use and delete the others out of the folder structure.



Andrew

Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: Hacked Site
« Reply #7 on: January 24, 2006, 09:09:58 AM »

WS FTP couldn't create the folders?  Hmmm...if you are one of our free hosting accounts are you a subdomain of Webs 4 Christ?  That might account for it, but not likely.

I think you will find that SMF is hands down a better, faster BBS than YaBBSe

peace

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  Mambo - Joomla  |  General Discussions  |  Topic: Hacked Site « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!