<! sites hacked by malware

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
mikemcvey
Forum Members
Forum Members
Posts: 61
Joined: Tue May 02, 2006 4:08 am

<! sites hacked by malware

Post by mikemcvey »

Hi,

I have just had 3 sites hacked by malware.

It has inserted malicious iFrames and code into 2 files (bottom of index.php & top of includes.php).
My local version of the sites is OK.. so how did the code get in?
I have all my permissions set at 644.....

Any ideas how to stop it happening again?

Mike
User avatar
Augustas
Forum Members
Forum Members
Posts: 241
Joined: Wed Oct 17, 2007 6:09 pm
Location: the world

Re: <! sites hacked by malware

Post by Augustas »

Which version of CMSMS are you running?
If older than 1.2.5 then upgrade your CMSMS immidiately and also read here:

http://forum.cmsmadesimple.org/index.ph ... 09186.html
http://FollowTheRoad.com/ - living on the road...
http://www.kligys.com/ - asmeninis blog'as...
mikemcvey
Forum Members
Forum Members
Posts: 61
Joined: Tue May 02, 2006 4:08 am

Re: <! sites hacked by malware

Post by mikemcvey »

Thanks for the info...

I was running...
1.2 Barbados

Will upgrade ASAP.... do I really need to delete the database?
Quite a few edits since last backup so prefer not too...

Mike
User avatar
Dr.CSS
Moderator
Moderator
Posts: 12711
Joined: Thu Mar 09, 2006 5:32 am
Location: Arizona

Re: <! sites hacked by malware

Post by Dr.CSS »

You may try to just delete all FILES/FOLDERS then replace all files/folders from the original 1.2 and add any files/folders you may have added since first install and it should be good to go, but go thru whole site to make sure, then do an upgrade ASAP...
User avatar
Augustas
Forum Members
Forum Members
Posts: 241
Joined: Wed Oct 17, 2007 6:09 pm
Location: the world

Re: <! sites hacked by malware

Post by Augustas »

Would be recommendable to delete DB and overwrite with database backup as well.
2 months ago my 1.2.4 CMSMS site was hacked as well. I did carefull search of any changes made by hackers and I found nothing in the database. But who knows if your hack was the same like mine (probably not).

You might want look through your database and and if you see nothing suspisious, you might keep it.
You could use Winmerge program for looking for the differences between dump of you current Mysql and last DB backup.
But overerite ALL folders and files from the scratch, and change all the passwords (including MySQL logins).
http://FollowTheRoad.com/ - living on the road...
http://www.kligys.com/ - asmeninis blog'as...
Post Reply

Return to “CMSMS Core”