Question about a hacked site

For questions and problems with the CMS core. This board is NOT for any 3rd party modules, addons, PHP scripts or anything NOT distributed with the CMS made simple package itself.
Post Reply
User avatar
johnbmcdonald
Forum Members
Forum Members
Posts: 60
Joined: Mon May 14, 2007 8:01 pm
Location: Edmond, OK, USA

Question about a hacked site

Post by johnbmcdonald »

I built a site for a client a while back. after that, you guys released a new version.

At that time I tried to login to their site to upgrade it, but I couldn't login.

I guessed they changed their password or I had the wrong one or something..

So I sent them an email letting them know they needed to upgrade, which they never did.

I don't believe they never made a backup...

They've since contacted me. They've been hacked because in the admin panel appears:

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

CalGuy advised:

You need to
a) delete everything from your site (all files, and all tables in the cms database)
b) restore from a known good backup
c) change all CMS passwords
d) upgrade to CMS 1.2.5


My Question is, and I suspect I already know they answer...
Without a backup,  Does the site have to be rebuilt from scratch?
can't use any of the database tables? If I have to start from scratch, I might as well go with 1.3.1, yes?

Thanks
John
Last edited by Rolf on Mon Apr 02, 2012 1:39 pm, edited 1 time in total.
Reason: removed possible hacked code/links
Pierre M.

Re: Question about a hacked site

Post by Pierre M. »

Yes, erase-destroy, folders and database. http://forum.cmsmadesimple.org/index.ph ... #msg114458

And yes : from scratch => from latest official stable version, 1.3.1 today.

Remember http://wiki.cmsmadesimple.org/index.php ... mall_Guide
URL filtering can catch crack attempts whatever the CMSms version behind.

If you have no sane backup, may be you have at least a static mirror copy from wget or httrack ? or Google cache ?

Pierre M.
jmcgin51
Power Poster
Power Poster
Posts: 1899
Joined: Mon Jun 12, 2006 9:02 pm

Re: Question about a hacked site

Post by jmcgin51 »

You can retrieve lost login info as described in this thread:
http://forum.cmsmadesimple.org/index.ph ... 467.0.html

(assumes you have db access)

You MIGHT be able to re-use your database, but unless you do a pretty exhaustive analysis of the db, you're not going to be able to be sure that it's clean.  You might check with your webhost; often they do daily db and file backups, so you could ask them for a backup from a pre-hack date.
viebig

Re: Question about a hacked site

Post by viebig »

how big is this site, which modules it´s using?
Post Reply

Return to “CMSMS Core”