News:

Want to get involved in developing SMF, then why not lend a hand on our github!

Main Menu

My Forum got hacked by: SnakE1095

Started by I AM Legend, October 20, 2008, 02:25:01 AM

Previous topic - Next topic

I AM Legend

Hi All,
I went to log my forum to find to screen saying SnakE1095 was here
HaCkeD By

~ SnakE1095 ~

..  Shame On You  ...

You have awful security .. DuDe


  Greetz 2 : SnipeR CoDe



[email protected]

.. ][ S1A ][ ..

Any help would be awesome

DirtRider

#1
A link may help and the version of SMF you are running
http://www.triumphtalk.com

"The real question is not whether machines think but whether men do. "


DirtRider

Not good to hear on 1.1.6. Anyway looks like you will need to replace your index.php with a backup.
http://www.triumphtalk.com

"The real question is not whether machines think but whether men do. "

I AM Legend

what do i do about improving my security?

DirtRider

Well this is the thing I think you should make out a bug report seeing it is 1.1.6. I would also contact your host as 1.1.6 is supposed to be secure
http://www.triumphtalk.com

"The real question is not whether machines think but whether men do. "

I AM Legend

ok thanks for the help, any other info you come across please post it.
Thanks as always

Nathaniel

Specifically, you should fill out a security report. You can do that at the page below:
http://www.simplemachines.org/about/security.php

Also, as DirtRider said. Its possible that they may have used an issue with your server configueration or another script on your website. You should ask your host about it.
SMF Friend (Former Support Specialist) | SimplePortal Developer
My SMF Mods | SimplePortal

"Quis custodiet ipsos custodes?" - Who will Guard the Guards?

Please don't send me ANY support related PMs. I will just delete them.

I AM Legend

#8
Hey,
In the security report. where do I find Server Software?, PHP Version. MySQL Version? server accesslog?

Nathaniel

They should be in your hosting account area. If they aren't then you will have to ask your host what your server specs are.
SMF Friend (Former Support Specialist) | SimplePortal Developer
My SMF Mods | SimplePortal

"Quis custodiet ipsos custodes?" - Who will Guard the Guards?

Please don't send me ANY support related PMs. I will just delete them.

SA™

Quote from: I AM Legend on October 20, 2008, 02:25:01 AM
Hi All,
I went to log my forum to find to screen saying SnakE1095 was here
HaCkeD By

~ SnakE1095 ~

..  Shame On You  ...

You have awful security .. DuDe


  Greetz 2 : SnipeR CoDe



[email protected]

.. ][ S1A ][ ..

Any help would be awesome


seems thsi person is going after everyone i know lol i run i site called stoned freeroam and that has getting hacked nealy everyother day by that same person

it turned out to be a server exploit and not smf it hasnt happend since they fixed it
http://samods.github.io/SAChatBar/

Xbox Live: smokerthecheese 360 or xbone
My Work
Piano Movers / Delivery service
QuoteMy allies are dead.
I'm 'bout to be too.
Zombies are chasing me.
F*** it, I'm screwed -___-

I AM Legend


SA™

http://samods.github.io/SAChatBar/

Xbox Live: smokerthecheese 360 or xbone
My Work
Piano Movers / Delivery service
QuoteMy allies are dead.
I'm 'bout to be too.
Zombies are chasing me.
F*** it, I'm screwed -___-

I AM Legend


I AM Legend

have been in contact with my host, waiting to see what they have to say on this matter, will keep you informed

I AM Legend

Hi All,
ok my host says it is not a server exploit,
they said:

Please ensure you are fully up to date with security patches etc for. Aside from that you have full 777 permissions on some of your files and directories which leave your website open to exploitation. Please refer to your forum's help files for changing permissions to the correct levels.

If you require further assistance from us please let us know.

I am going to need help on changing permissions to safe guard my site from future attacks of this type, I will need a list of files/phps that should never be 0777 so I can go and change permissions to safe guard this ever happening again, only smf can help me with this.

I have also asked my host to provide me with the info below:
Server Platform
Server Software
PHP Version
MySQL Version
Server accesslog (Please only send us the logs from around the time the intrusion occured)
Url of PHPinfo file

as soon as I receive it, I will fill out a security report for smf.

In the mean time, any help on the permissions issue would be great.
Thanks as always.

I AM Legend

any help on permissions would be great ???

Nathaniel

Well, chmod 777 isn't really a security risk (read the documentation below), although you may want to change your 'Settings.php' file so that it isn't chmoded to 0777.

Why chmod 777 is NOT a security risk
SMF Friend (Former Support Specialist) | SimplePortal Developer
My SMF Mods | SimplePortal

"Quis custodiet ipsos custodes?" - Who will Guard the Guards?

Please don't send me ANY support related PMs. I will just delete them.

I AM Legend

#18
Hi,
ok so is that it,
change the settings.php from 0777 to what? 644 or 766?
what else do i need to do to stop this happening again?
the index.php file was changed on the day of the hack, how do i stop that happening again?
the attachment here was the index file that was used, pull it into a firefox browser and you will see what I saw.
surely it cant be as simple as changing the settings.php file to 644 or 766 or something and this wont happen again?
thanks as always

ChainLightning

I took a quick look at my Settings.php and it's set to 644.  Out of curiosity, I checked my index.php and it was set the same, 644.

I can't help you with how to stop it from happening again. I don't know enough about hacking to know how he did it. :( Hopefully, someone else will have an idea or two.

Advertisement: