CMS has been hacked

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
devilslayer
Forum Members
Forum Members
Posts: 41
Joined: Sat Apr 23, 2005 11:38 pm

CMS has been hacked

Post by devilslayer »

My index.php file has been hacked somehow.
See below (line 53-68):

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I also had this happen to another website that doesn't use CMS Made Simple. I had exactly the same IFRAME inserted within the static HTML homepage of the website.

;http://www.royalengineersforums.co.uk

I have deleted the other website and put up a message explaining why.

How is this person (xxxxxxxxxx) managing to change files on my web server.

I need to know what is happening here, so I can tie down the security to stop it.
Last edited by Rolf on Mon Apr 02, 2012 12:39 pm, edited 1 time in total.
Reason: removed hacked code/links
ID2020
Forum Members
Forum Members
Posts: 39
Joined: Wed Feb 08, 2006 12:47 am

Re: CMS has been hacked

Post by ID2020 »

Where you using the same passwords for both sites perhaps?

Or used it on the site somewhere?

???
Signex

Re: CMS has been hacked

Post by Signex »

is it on shared hosting?
devilslayer
Forum Members
Forum Members
Posts: 41
Joined: Sat Apr 23, 2005 11:38 pm

Re: CMS has been hacked

Post by devilslayer »

Signex wrote: is it on shared hosting?
It is a reseller account, so I suppose the answer is yes.

Are you saying that this individual has access to my web server?
mager
Forum Members
Forum Members
Posts: 44
Joined: Wed Apr 04, 2007 2:25 pm

Re: CMS has been hacked

Post by mager »

Quick answer: yes!

Though I don't know if he came through CMSMS, trough the filesystem or through MYSQL.

I'd change all passwords right now.

Martin
devilslayer
Forum Members
Forum Members
Posts: 41
Joined: Sat Apr 23, 2005 11:38 pm

Re: CMS has been hacked

Post by devilslayer »

mager wrote: Quick answer: yes!

Though I don't know if he came through CMSMS, trough the filesystem or through MYSQL.

I'd change all passwords right now.

Martin
How do I reinstate the website? Could I grab a clean index.php file from the default install and replace the hacked one with it?
reneh
Dev Team Member
Dev Team Member
Posts: 446
Joined: Tue Nov 28, 2006 8:39 pm

Re: CMS has been hacked

Post by reneh »

I have seen and experienced taht type of hack myself. That time it was trough the filesystem (ftp or something).


To be sure that all files are clean - upload all files for that version again.

"> if one file is hacked there is no trusting on the rest either"

Good luck!


NB!
Be sure to runn the latest stabel version of CMSMS!  Security holdes are found in older versions and these are closed in v1.1+
Last edited by reneh on Mon Jul 23, 2007 11:10 am, edited 1 time in total.
ReneH 8-)
A search will save you hours waiting for an answer! Image
Post Reply

Return to “CMSMS Core”