Did my CMSMS get hacked ? [SOLVED - kind of]

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Locked
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Did my CMSMS get hacked ? [SOLVED - kind of]

Post by thomahawk »

We found a code snippet at the end of the index.php. Usually it ends like this

# vim:ts=4 sw=4 noet
?>


but at one website (thanks to a Norton warning) I found this at the end of the page

I first thought I had this put in for pretty URL's but as far as I understand it, it does something different. Or someone knows this?

Thanks for your feedback
Thom
Last edited by thomahawk on Fri Dec 12, 2014 8:32 pm, edited 2 times in total.
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Re: Did my CMSMS get hacked ?

Post by thomahawk »

We found the same code in several other pages too.
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: Did my CMSMS get hacked ?

Post by Jo Morg »

That code is not part of the official release. It's a possible infection.

* note: pasting those code spinets is not allowed as they are signatures by which virus can be identified and may blacklist the forum.
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Re: Did my CMSMS get hacked ?

Post by thomahawk »

Ok, thanks. Well, after so many years with CMSMS, I have never seen a hacked site. Is it possible to change index.php through CMSMS itself? Or only by hacking FTP?
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: Did my CMSMS get hacked ?

Post by Jo Morg »

r=&sv=0&sc=1&sf=all&sk=t&sd=d&sr=posts&st=0&ch=300&t=0&submit=Search

There are even a few topics about steps to recover from possible hacks.

Keep in mind that CMSMS is not the weak link in all the of occurrences I know of.
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Re: Did my CMSMS get hacked ?

Post by thomahawk »

Well, one of your team thinks its originally a wordpress virus. I would be very surprised if the problem was CMSMS, because I always take the recommended security measures, setting most limited ftp permissions to files, rename the admin folder and so on.
User avatar
Dr.CSS
Moderator
Moderator
Posts: 12711
Joined: Thu Mar 09, 2006 5:32 am

Re: Did my CMSMS get hacked ?

Post by Dr.CSS »

If you found strange code in your index.php you can remove it and replace it with a fresh one from the tar.gz of the same cmsms version, unpack and upload to site...
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: Did my CMSMS get hacked ?

Post by Jo Morg »

Bummer I originally wanted to post this link:
http://forum.cmsmadesimple.org/posting.php?
Something went wrong sorry.
thomahawk wrote:Well, one of your team thinks its originally a wordpress virus.
Most possibly. And sorry for my previous quite cryptic post... :)
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Re: Did my CMSMS get hacked ?

Post by thomahawk »

Jo, the second link also seems to be wrong. For me it only opens a new post form.
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: Did my CMSMS get hacked ?

Post by Jo Morg »

Not on my best days... and the stupid keyboard is not helping either...

Let's try again: http://forum.cmsmadesimple.org/search.p ... rds=hacked


::)
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: Did my CMSMS get hacked ?

Post by Jo Morg »

http://forum.cmsmadesimple.org/viewtopi ... 28&t=69570
this is possibly one of the best topics about it.
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
User avatar
thomahawk
Power Poster
Power Poster
Posts: 312
Joined: Fri Jul 25, 2008 10:13 am

Re: Did my CMSMS get hacked ? [SOLVED - kind of]

Post by thomahawk »

Okay, it seems somehow there was a worpress installation running on that hosting, or however, a wordpress virus got in or was there and infected php files of the same name and location as they would be in a wordpress installation. This happened not just now, but about a year ago on first CMSMS install. About 11 php files where infected. Not a serious virus, just data collection as it seems, and the collectors server not active anymore.

However, we used that for making a upgrade of CMSMS and get rid of the infected files. Could have been done manually too on that 11 files. Hope that bugger does not come back again.
Locked

Return to “CMSMS Core”