HELP- Search module or site hacked or phished, or not?

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
burlington
Power Poster
Power Poster
Posts: 444
Joined: Wed Dec 27, 2006 5:15 pm

HELP- Search module or site hacked or phished, or not?

Post by burlington »

Website was upgraded last month to latest CMSMS version 1.11.13.

'Search' module files show changes/creation dates at the time of the upgrade, 23/3/15. HOWEVER, there is a file ini.php which is dated 10/4/15.

I raise this question because the site owner has had an email from '<noreply@google.com>' which states:
<quote>
Below are one or more example URLs on your site which may be part of a phishing attack:
http://www.xyz.co.uk/modules/Search/templates
http://www.xyz.co.uk/modules/Search/templates/
http://www.xyz.co.uk/modules/Search/templates/index.html
</quote>

Any ideas folks?

Many thanks

Martin
Last edited by velden on Fri Apr 17, 2015 8:28 am, edited 1 time in total.
Reason: Please use forum option 'Do not automatically parse URLs' when using fake urls
staartmees
Power Poster
Power Poster
Posts: 1049
Joined: Wed Mar 19, 2008 4:54 pm

Re: HELP- Search module or site hacked or phished, or not?

Post by staartmees »

I don't think the email is really from the email address "noreply@ google.com", it was probably spoofed. Bet if you clicked on 'reply' you would be sending an email to an email address that is not "noreply@ google.com".
User avatar
Jo Morg
Dev Team Member
Dev Team Member
Posts: 1973
Joined: Mon Jan 29, 2007 4:47 pm

Re: HELP- Search module or site hacked or phished, or not?

Post by Jo Morg »

burlington wrote:Any ideas folks?
Did you actually try any of those links in your own site to see what happens?
In all CMSMS distributions all directories created or used by the core have an index.html file with the following content:

Code: Select all

<!-- dummy index.html -->
which would display a blank page in any case.
That is what you should find there, and nothing else. If there is some other page, you should be looking for security problems with your host. Typically this is not a CMSMS problem.
"There are 10 types of people in this world, those who understand binary... and those who don't."
* by the way: English is NOT my native language (sorry for any mistakes...).
Code of Condut | CMSMS Docs | Help Support CMSMS
My developer Page on the Forge
GeekMoot 2015 in Ghent, Belgium: I was there!
GeekMoot 2016 in Leicester, UK: I was there!
DevMoot 2023 in Cynwyd, Wales: I was there!
Post Reply

Return to “CMSMS Core”