I've been using CMSMS for a while now and no problems until about a month ago when a site I did in CMSMS got hacked. The hacker somehow appended a lot of HTML to the end of include.php, no idea how they did it, it was an older version of CMSMS, so I posted in here and was told to upgrade which I did to 1.3, today the site was hacked again in exactly the same way, lots of links to viagra sites at the end of the include.php file.
I've checked the file permissions and they are correct, I've also changed the FTP password, downloading 1.3.1 now, is this a known problem ?
CMSMS Hacked again...
CMSMS Hacked again...
Regards,
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Re: CMSMS Hacked again...
Sorry, which log files?
Regards,
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Re: CMSMS Hacked again...
Since this would appear to be either an ongoing issue with cmsms, or your host, and since it would be helpful to start establishing a possible pattern, can you say who is your hosting provider?
Re: CMSMS Hacked again...
If it's the one in his sig, it looks like a godaddy site.
Re: CMSMS Hacked again...
Yes, its http://www.eska.co.uk and yes it is hosted by http://www.godaddy.com, however I have several other sites also hosted by godaddy.com and these are not based on CMSMS and have been up longer, but have never been hacked.
Regards,
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Re: CMSMS Hacked again...
Have you cleaned your old install before?Sy wrote: it was an older version of CMSMS, so I posted in here and was told to upgrade which I did to 1.3, today the site was hacked again in exactly the same way, lots of links to viagra sites at the end of the include.php file.
In current hacks there are many files uploaded (sometimes). If these files are online hackers have no problem to get access.
Have you realized all of security help?
http://wiki.cmsmadesimple.org/index.php ... mall_Guide
Re: CMSMS Hacked again...
Thank you, I will go through the document.
Regards,
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com
Sy

Sites built with CMSMS:
http://www.eska.co.uk, http://avasig.com, http://www.pygmygoats.co.uk, http://www.agsbuildersltd.com, http://onlineslotracing.com