Page 1 of 1

Was hacked... ver. 1.2.3 :(

Posted: Mon Oct 06, 2008 9:50 pm
by Janny111
Hi all.
My site was hacked, after that I saw many spammy links in header and body of my site... (admin panel too)
I clean up index.php, include.php and some other files, also I find some kind of "web browser" in my postlet folder - deleted and closed via .htaccess.
But links still there :(

I know that ver. is old and now i'm planning to upgrade it.
I have no backups and my data is very important, i can't just delete all. :(

Help pls :'(


Janny.

Re: Was hacked... ver. 1.2.3 :(

Posted: Mon Oct 06, 2008 10:29 pm
by nhaack
I have no backups and my data is very important
How could you...lesson learned I would say ;) (I know... it's sarcastic... but if you have important stuff... back it up!)

Ok, back to your problem:

I had someting like this with a static old site i nearly forgot about... I do not know how... but they got in it via FTP (luckily only a limited account), spammed each folder with tons of HTML pages that where full of pills, porn and poker links. Then they pasted html into my pages that refered to these created pages and external ones... of whcih the links looked pretty much like what I got). It was as if a bot just grabbed every file and pasted links to these files into the code. I guess this is how you push your ranking results in the 3P Business.

Cleaning was ok for me since I only had 3 static pages... have you looked into your database, probably they left that out? what is the content saying? If your DB is ok and only your files where corrupted, backup DB, flush everything, change all passwords of all accesses (FTP, DB, etc). Reinstall CMSMS and upload your backup to the DB...

I hope that you could find some help...

oh... and you should probably notify your hosting provider and report the incident to the police.

Oh dear... the web is like a big city... being smaller... you could park your car unclosed at night at a dark side-alley. But now you carry around a whole garage with you, so your car doesn't get hijacked while you drive on the highway during day.

Best
Nils

Re: Was hacked... ver. 1.2.3 :(

Posted: Mon Oct 06, 2008 11:12 pm
by toto
Hey friends its so stupid they hacks our sites every day, last week they hack 2 my sms made sites. Today they hacked onother. Its bad game they hack us, and we stay and just backup, dellete stupid spam, porn, pills HTML pages and ahve noting to do. I have strong security and agayn index.php has hacked.
stupid game...

Re: Was hacked... ver. 1.2.3 :(

Posted: Tue Oct 07, 2008 7:05 am
by alby
Here there are a few steps if you have not hija in DB


Alby

Re: Was hacked... ver. 1.2.3 :(

Posted: Tue Oct 07, 2008 9:00 pm
by Janny111
Hi,
thanks all for help, problem solved ;)
db was uncorrupted, just reupload index.php and inlude.php, after that my old ver. became clean from spam.
but i'm renew version (clean install).

lesson learned, you r right, nhaack.
nah police :D that was my fault, now i will be check for updates ;D

thanks again,
Jenny.

Re: Was hacked... ver. 1.2.3 :(

Posted: Tue Oct 07, 2008 10:24 pm
by toto
how are you shoure that they can hack your site tomorow? Yes you replace today index.php but they can hack you tomorrow.
What is the problem with index.php does anybody know?

Re: Was hacked... ver. 1.2.3 :(

Posted: Wed Oct 08, 2008 6:57 am
by alby
toto wrote: how are you shoure that they can hack your site tomorow? Yes you replace today index.php but they can hack you tomorrow.
What is the problem with index.php does anybody know?
Yes if you have bad scripts in files or DB.
Here is the importance of a good cleaning ...

Alby

Re: Was hacked... ver. 1.2.3 :(

Posted: Wed Oct 08, 2008 3:59 pm
by Pierre M.
alby wrote: Here is the importance of a good cleaning ...
And preventive hardening. A webserver has locks, just use them. And stay uptodate (1.4.1 today).

Pierre

Re: Was hacked... ver. 1.2.3 :(

Posted: Wed Oct 08, 2008 5:27 pm
by toto
Thank you Alby, what do you mean bad scripts or DB?

Re: Was hacked... ver. 1.2.3 :(

Posted: Wed Oct 08, 2008 7:13 pm
by alby
toto wrote: Thank you Alby, what do you mean bad scripts or DB?
ex: index.php or include.php hacked or iframe tag in template DB
all codes not your ...

Alby