CMS site hacked - links hikacked [SOLVED]

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
gingercat
Forum Members
Forum Members
Posts: 53
Joined: Mon Aug 04, 2008 2:24 am

CMS site hacked - links hikacked [SOLVED]

Post by gingercat »

replaced index.php - problem solved extra code added to index.php which I didn't notice because I was reading my local copy of the file instead of downloading it from the server first. The hack was very crude. A div added to the end of the file containing about 10 links. The reason it appeared the home link was overwritten was because these links were at the top left of the screen although invisible.

I have a standard CMS install (1.11.1) on a windows 2003 server with php 5.2.9 and noticed that a couple of the menu links have been hijacked to send users to sales sites that have nothing to do with this one. Its an old site but the version of CMSMS has been updated

When you view the HTML page source the urls are correct.

Usually I can find these by looking for new script files on the server - there were a few (php and asp) which I removed but the hack remains

When you click the home link it diverts to another web site altogether

Ideally I'd like to fix it without re-uninstalling - Has anyone come across this before and if so what was the fix?

if this should be in another section of the forum please move it there
Last edited by gingercat on Sun Jul 13, 2014 8:19 pm, edited 1 time in total.
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1967
Joined: Mon Jan 29, 2007 4:47 pm

Re: CMS site hacked - links hikacked [SOLVED]

Post by Jo Morg »

Just for future reference, can you give more details on what happened, and what was the fix?
(Without posting any code to avoid having the forum blacklisted by the Search Engines)
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
Post Reply

Return to “CMSMS Core”