My site was hacked - while running 1.2.5
Posted: Fri Jun 06, 2008 3:23 pm
Hate to say it guys but 1.2.5 is not safe and we should all be aware of this one. I was hacked on that version but was able to recoup fairly fast due to good backups. It is a hassle though. It was the same admin hack I believe that people have been seeing in the 1.2.4 or earlier versions. It was the one where you went to login via the admin and there were about 5-6 errors above it. I can't remember what it said as I tried to rebuild the site fast but I hope this post helps.
THIS WAS DEF A CMSMS HACK - NO OTHER FILES, DBs OR PASSWORDS HAVE BEEN CHANGED OR STOLEN.
WHAT WAS AFFECTED:
When I noticed it, the fonts were larger than normal on the front end which was a small but but absolutely odd. At that point, I logged in to see if something was off with my CSS and I noticed the admin login page had an error message people were getting on the last version when the admin panel had been comp'd. I can't remember what the error was but it was in the forum at the time I researched it so I didn't bother documenting. On the fresh install, I immediately changed the location of the admin folder and of course all login info. After looking into with minimal time, I noticed that they were able to place a nonsense javascript in the head of all of the templates which was blowing out the page formatting (but the site still worked overall) and I am sure some modules/scripts if I dug further.
When I logged into the admin, I noticed a lot of modules that use tab interfaces within the admin were no longer working. The same tag had to be blowing out the admin pages as well. Needless to say, without the tabs working - CMSMS admin is inoperable.
MY TAKE:
This was def a CMSMS hack specifically. I wouldn't be surprised if this clown searched Google for Powered by CMSMS and attacked form there. The bottom line: he couldn't do much but insert some hidden files (that I could not locate) and call them from the head of the of the templates. Everything else was intact and the site still fully operated with NO visual errors other than the larger than normal text (for the most part)? It was as if they javascript he inserted was partially erroring out some formatting. But overall, the site was fully functional and oddly enough - 90% of the styles worked correctly.
Thanks guys and I wish I saved more info. Unfort - this was my live consulting website so when I realized I could not fix what was there, I completely reuploaded and relaunched. Unfort - this will happen again and next time I will save some code/screens.
-Jack
THIS WAS DEF A CMSMS HACK - NO OTHER FILES, DBs OR PASSWORDS HAVE BEEN CHANGED OR STOLEN.
WHAT WAS AFFECTED:
When I noticed it, the fonts were larger than normal on the front end which was a small but but absolutely odd. At that point, I logged in to see if something was off with my CSS and I noticed the admin login page had an error message people were getting on the last version when the admin panel had been comp'd. I can't remember what the error was but it was in the forum at the time I researched it so I didn't bother documenting. On the fresh install, I immediately changed the location of the admin folder and of course all login info. After looking into with minimal time, I noticed that they were able to place a nonsense javascript in the head of all of the templates which was blowing out the page formatting (but the site still worked overall) and I am sure some modules/scripts if I dug further.
When I logged into the admin, I noticed a lot of modules that use tab interfaces within the admin were no longer working. The same tag had to be blowing out the admin pages as well. Needless to say, without the tabs working - CMSMS admin is inoperable.
MY TAKE:
This was def a CMSMS hack specifically. I wouldn't be surprised if this clown searched Google for Powered by CMSMS and attacked form there. The bottom line: he couldn't do much but insert some hidden files (that I could not locate) and call them from the head of the of the templates. Everything else was intact and the site still fully operated with NO visual errors other than the larger than normal text (for the most part)? It was as if they javascript he inserted was partially erroring out some formatting. But overall, the site was fully functional and oddly enough - 90% of the styles worked correctly.
Thanks guys and I wish I saved more info. Unfort - this was my live consulting website so when I realized I could not fix what was there, I completely reuploaded and relaunched. Unfort - this will happen again and next time I will save some code/screens.
-Jack