Suggestion for hacked sites

Talk about new features for CMSMS and modules.
Post Reply
kgiles
New Member
New Member
Posts: 3
Joined: Fri Sep 16, 2011 1:27 pm

Suggestion for hacked sites

Post by kgiles »

Hi
I think CMSMS is a great program, the only problem I have had is I have had 6 sites hacked in the last 6 months. Usually spammers.
Yes They may not have been the latest versions.. but they were close. The problem is once the site has been compromised it is difficult to find and remove non CMSMS files.
My suggestion is to have a feature in admin that compares the files in the site with the files for the release. and lists all non CMSMS files. content compare would be even better except for files that change config etc.
Thanks for your consideration and keep up the great work
Keith
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: Suggestion for hacked sites

Post by RonnyK »

I dont know how recent your versions are, but since at least 2 years, the version have SystemVerification inside, which can compare the original files with the current ones in the install. The check-file is downloadable in the Download-area, and can be compared to your install.

Ronny
gianpiero
Forum Members
Forum Members
Posts: 221
Joined: Sun Jan 07, 2007 4:32 pm
Location: Italy

Re: Suggestion for hacked sites

Post by gianpiero »

anyway a lot of softwares do this, in FTP mode also
kgiles
New Member
New Member
Posts: 3
Joined: Fri Sep 16, 2011 1:27 pm

Re: Suggestion for hacked sites

Post by kgiles »

Thanks for tip Ronny,
I had missed this feature... if it lists additional non cmsms files it would be what I need. but I just tried it and it didn't list any of the files I had uploaded in the site so I suspect it wont find additional spammer files???
anyone know??
Keith
gianpiero
Forum Members
Forum Members
Posts: 221
Joined: Sun Jan 07, 2007 4:32 pm
Location: Italy

Re: Suggestion for hacked sites

Post by gianpiero »

malicious code are into database normally, and overwrite/modify or add code into your template, news, css, article ...

search <__iframe> tag calling external site or other <www> into database

bye
Mieszko
Forum Members
Forum Members
Posts: 59
Joined: Fri Mar 04, 2011 2:40 pm

Re: Suggestion for hacked sites

Post by Mieszko »

anyway a lot of softwares do this, in FTP mode also
Which software for example?
Can you name any?
Would find that information very helpful.
Thank you.
gianpiero
Forum Members
Forum Members
Posts: 221
Joined: Sun Jan 07, 2007 4:32 pm
Location: Italy

Re: Suggestion for hacked sites

Post by gianpiero »

I use Beyond Compare that's an ftp client also.

N.B. .hope I'm not infringing forum rules when quoting commercial product :-[

anyway try googling "file compare" for a free one
Mieszko
Forum Members
Forum Members
Posts: 59
Joined: Fri Mar 04, 2011 2:40 pm

Re: Suggestion for hacked sites

Post by Mieszko »

Thank you very much.
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: Suggestion for hacked sites

Post by RonnyK »

In terms of checking. You can generate your own checksum as well. This means that you can test the default upload/install. Whne you installed modules etc, you can go to SystemVerification, and create a set for your current setup. And use that for comparison at a later moment.

Ronny
gianpiero
Forum Members
Forum Members
Posts: 221
Joined: Sun Jan 07, 2007 4:32 pm
Location: Italy

Re: Suggestion for hacked sites

Post by gianpiero »

@RonnyK

have you ever seen a site has been hacked through
modification of php files ? most of them are hacked via db, I suppose

thanks
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: Suggestion for hacked sites

Post by RonnyK »

gianpiero,

most hacked sites that I saw, where indeed modified php-files. They mostly originated from x-access on shared-hosts.

Ronny
gianpiero
Forum Members
Forum Members
Posts: 221
Joined: Sun Jan 07, 2007 4:32 pm
Location: Italy

Re: Suggestion for hacked sites

Post by gianpiero »

Thanks :)
replytomk3

Re: Suggestion for hacked sites

Post by replytomk3 »

Most hacks are thru SHARED hosting accounts.

To find if your site is still infected, download whole site by FTP, and scan those files with Avast!

Search for my posts on this.
Post Reply

Return to “Feature ideas”