My index.php file has been hacked somehow.
See below (line 53-68):
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I also had this happen to another website that doesn't use CMS Made Simple. I had exactly the same IFRAME inserted within the static HTML homepage of the website.
;http://www.royalengineersforums.co.uk
I have deleted the other website and put up a message explaining why.
How is this person (xxxxxxxxxx) managing to change files on my web server.
I need to know what is happening here, so I can tie down the security to stop it.
CMS has been hacked
-
devilslayer
- Forum Members

- Posts: 41
- Joined: Sat Apr 23, 2005 11:38 pm
CMS has been hacked
Last edited by Rolf on Mon Apr 02, 2012 12:39 pm, edited 1 time in total.
Reason: removed hacked code/links
Reason: removed hacked code/links
Re: CMS has been hacked
Where you using the same passwords for both sites perhaps?
Or used it on the site somewhere?

Or used it on the site somewhere?
-
devilslayer
- Forum Members

- Posts: 41
- Joined: Sat Apr 23, 2005 11:38 pm
Re: CMS has been hacked
It is a reseller account, so I suppose the answer is yes.Signex wrote: is it on shared hosting?
Are you saying that this individual has access to my web server?
Re: CMS has been hacked
Quick answer: yes!
Though I don't know if he came through CMSMS, trough the filesystem or through MYSQL.
I'd change all passwords right now.
Martin
Though I don't know if he came through CMSMS, trough the filesystem or through MYSQL.
I'd change all passwords right now.
Martin
-
devilslayer
- Forum Members

- Posts: 41
- Joined: Sat Apr 23, 2005 11:38 pm
Re: CMS has been hacked
How do I reinstate the website? Could I grab a clean index.php file from the default install and replace the hacked one with it?mager wrote: Quick answer: yes!
Though I don't know if he came through CMSMS, trough the filesystem or through MYSQL.
I'd change all passwords right now.
Martin
Re: CMS has been hacked
I have seen and experienced taht type of hack myself. That time it was trough the filesystem (ftp or something).
To be sure that all files are clean - upload all files for that version again.
"> if one file is hacked there is no trusting on the rest either"
Good luck!
NB!
Be sure to runn the latest stabel version of CMSMS! Security holdes are found in older versions and these are closed in v1.1+
To be sure that all files are clean - upload all files for that version again.
"> if one file is hacked there is no trusting on the rest either"
Good luck!
NB!
Be sure to runn the latest stabel version of CMSMS! Security holdes are found in older versions and these are closed in v1.1+
Last edited by reneh on Mon Jul 23, 2007 11:10 am, edited 1 time in total.
ReneH 
A search will save you hours waiting for an answer!
A search will save you hours waiting for an answer!


