Page 1 of 1

CMSMS Hacked again...

Posted: Wed Jun 25, 2008 1:32 pm
by Sy
I've been using CMSMS for a while now and no problems until about a month ago when a site I did in CMSMS got hacked.  The hacker somehow appended a lot of HTML to the end of include.php, no idea how they did it, it was an older version of CMSMS, so I posted in here and was told to upgrade which I did to 1.3, today the site was hacked again in exactly the same way, lots of links to viagra sites at the end of the include.php file.

I've checked the file permissions and they are correct, I've also changed the FTP password, downloading 1.3.1 now, is this a known problem ?

Re: CMSMS Hacked again...

Posted: Wed Jun 25, 2008 1:43 pm
by cyberman
Please check the logfiles ...

Re: CMSMS Hacked again...

Posted: Wed Jun 25, 2008 1:54 pm
by Sy
Sorry, which log files?

Re: CMSMS Hacked again...

Posted: Wed Jun 25, 2008 9:48 pm
by LC350
Since this would appear to be either an ongoing issue with cmsms, or your host, and since it would be helpful to start establishing a possible pattern, can you say who is your hosting provider?

Re: CMSMS Hacked again...

Posted: Wed Jun 25, 2008 11:39 pm
by Nullig
If it's the one in his sig, it looks like a godaddy site.

Re: CMSMS Hacked again...

Posted: Thu Jun 26, 2008 11:43 am
by Sy
Yes, its http://www.eska.co.uk and yes it is hosted by http://www.godaddy.com, however I have several other sites also hosted by godaddy.com and these are not based on CMSMS and have been up longer, but have never been hacked.

Re: CMSMS Hacked again...

Posted: Fri Jun 27, 2008 5:40 am
by cyberman
Sy wrote: it was an older version of CMSMS, so I posted in here and was told to upgrade which I did to 1.3, today the site was hacked again in exactly the same way, lots of links to viagra sites at the end of the include.php file.
Have you cleaned your old install before?

In current hacks there are many files uploaded (sometimes). If these files are online hackers have no problem to get access.

Have you realized all of security help?

http://wiki.cmsmadesimple.org/index.php ... mall_Guide

Re: CMSMS Hacked again...

Posted: Fri Jun 27, 2008 11:42 am
by Sy
Thank you, I will go through the document.