[SOLVED] Hacked, hacked, hacked!
-
- Forum Members
- Posts: 12
- Joined: Mon Nov 09, 2009 9:23 pm
[SOLVED] Hacked, hacked, hacked!
I keep getting hacked! I am doing all of the things the setup says to do. I even delete the install directory and change the permissions on the config file. Any ideas?
Last edited by QueenOfStarWears on Sat Dec 05, 2009 11:53 am, edited 1 time in total.
-
- Support Guru
- Posts: 8169
- Joined: Tue Oct 19, 2004 6:44 pm
- Location: Fernie British Columbia, Canada
Re: Hacked, hacked, hacked!
No information provided by you, gets you no help from us.
Follow me on twitter
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
Please post system information from "Extensions >> System Information" (there is a bbcode option) on all posts asking for assistance.
--------------------
If you can't bother explaining your problem well, you shouldn't expect much in the way of assistance.
-
- Forum Members
- Posts: 12
- Joined: Mon Nov 09, 2009 9:23 pm
Re: Hacked, hacked, hacked!
Many apologies. I'm using the latest version and worked with our unix admin to set up all of the permissions during installation. He then changed the config file permssions per the directions and I deleted the install directory.
I just got an angry message from him that he is not going to allow CMSMS again due to the hacking, but I don't know what else to tell him except to follow the directions during the installation.
If you could let me know what type of information you need, that would be helpful. I'll be glad to provide it.
I just got an angry message from him that he is not going to allow CMSMS again due to the hacking, but I don't know what else to tell him except to follow the directions during the installation.
If you could let me know what type of information you need, that would be helpful. I'll be glad to provide it.
Re: Hacked, hacked, hacked!
http://forum.cmsmadesimple.org/index.ph ... ,40.0.html
define "the latest version"
I believe there have been no reported hacks due to CMSMS holes for a very long time (maybe 1.2). Most reported hacks are FTP hacks, unclosed sessions on a public computer, etc. Not the fault of CMSMS, and your admin most likely knows (or should know) this.
The more details you can provide, the better we can help you. If it is in fact a breach via CMSMS, the dev team needs to know as much as possible so they can find/fix the issue.
define "the latest version"
I believe there have been no reported hacks due to CMSMS holes for a very long time (maybe 1.2). Most reported hacks are FTP hacks, unclosed sessions on a public computer, etc. Not the fault of CMSMS, and your admin most likely knows (or should know) this.
The more details you can provide, the better we can help you. If it is in fact a breach via CMSMS, the dev team needs to know as much as possible so they can find/fix the issue.
Re: Hacked, hacked, hacked!
Please go into your Admin, click on Site Admin > System Information and then click on the View Text Report link, and email the results to me and/or any of the core developers.
It'd also be helpful to learn if you are hosting on a dedicated or a shared server.
Also, please have your IT person attach the logs and any other information that they have indicating the breach was via CMS Made Simple. If possible, get them in touch with us directly, so we can do some forensic analysis.
Thanks,
___Samuel___
It'd also be helpful to learn if you are hosting on a dedicated or a shared server.
Also, please have your IT person attach the logs and any other information that they have indicating the breach was via CMS Made Simple. If possible, get them in touch with us directly, so we can do some forensic analysis.
Thanks,
___Samuel___
Many modules available from the http://dev.cmsmadesimple.org
The CMS Made Simple Developer Cookbook is now available from Packt Publishers!
The CMS Made Simple Developer Cookbook is now available from Packt Publishers!
Re: Hacked, hacked, hacked!
If your hosting provider blames CMSMS ask them to provide proof with server logs. If they can't, then it was actually likely their poor security that should be blamed.
Re: Hacked, hacked, hacked!
And one more thing that you can implement is URL filtering in your htaccess file (details available if you search here). But like it was said, no more holes have been seen with URL attacks.
Re: Hacked, hacked, hacked!
Hi,
Have you read this "How To" on the wiki site?
http://wiki.cmsmadesimple.org/index.php ... mall_Guide
If not, it may prove helpful.
Have you read this "How To" on the wiki site?
http://wiki.cmsmadesimple.org/index.php ... mall_Guide
If not, it may prove helpful.
Nearly all men can stand adversity, but if you want to test a man's character, give him power.
- Abraham Lincoln
- Abraham Lincoln
Re: Hacked, hacked, hacked!
Hi,
I have CMSMS on a debian linux box that is hardened. If you provide more details on your CMSMS config, the Linux OS you are using, and the basic config of the box, I might be able to help.
-p
I have CMSMS on a debian linux box that is hardened. If you provide more details on your CMSMS config, the Linux OS you are using, and the basic config of the box, I might be able to help.
-p
Re: Hacked, hacked, hacked!
By the way, I have intrusion protection, secure mailer, ssh-only (key-based) access, etc. All very secure.
pbrady wrote: Hi,
I have CMSMS on a debian linux box that is hardened. If you provide more details on your CMSMS config, the Linux OS you are using, and the basic config of the box, I might be able to help.
-p
-
- Forum Members
- Posts: 12
- Joined: Mon Nov 09, 2009 9:23 pm
[SOLVED] Re: Hacked, hacked, hacked!
Thanks to all! I took all of the advice (thanks for the helpful links) went back to the server admin with additional info. It appears to have been things my server admin needed to button down.
Last edited by QueenOfStarWears on Sat Dec 05, 2009 11:59 am, edited 1 time in total.