I've removed it now but how do I stop it happening again? Which file permissions? database password? admin login password?


Heeeelpp!!! Any suggestions on what to do greatly appreciated.
You should understand "how" you have been hacked.herbshirt wrote: How on earth did someone insert Google Ad's on my page? I found the code inserted into my template!
I've removed it now but how do I stop it happening again? Which file permissions? database password? admin login password?
also:alby wrote: ...
- server hacked
- from other site hacked (in a shared hosting) and config.php readable
- from other shared client in poor environment hosting and config.php readable
- hacked for a old vulnerability (your CMSMS version?). Check your server access log for "strange" url
- stolen the admin password?
Alby
View Apache docs (or google) for thisherbshirt wrote: I'm not sure what you mean... ".htpassword and .htaccess" ... I'll wait for the translation.
You must change name in config.php onlyherbshirt wrote: Also, when I change the name of the admin directory I have the feeling (obviously change my link to it etc etc) I'll need to change something elsewhere (config???)
herbshirt wrote: Yes I found the URL and sent them an email.
I found cubics.com I can't seem to find a relevant place to report them.
For start with .htaccess and .htpassword, you can read this article, it's very userful and detailed.herbshirt wrote: I'm not sure what you mean... ".htpassword and .htaccess" ... I'll wait for the translation.
Sticky? No, not IMO. A "securing" CMSms page on the wiki? Yes.Should this post become sticky??