Help.. i think i have been hacked.

Started by SN, July 26, 2010, 02:49:35 AM

Previous topic - Next topic

SN

i logged in my forum this morning and all of my boards have been renamed to ".By XA7M3D."

how can this happen? have i been hacked ?

chilly

smf version?
url?
installed mods?

thanks.

without further information i'd say it realy looks like your suggestion is correct.

Language Coordinator

SN

Link is in my profile click the globe

Im using RC3

It doesn't say ".By XA7M3D." on all my boards any more because i changed them back manually... i couldn't leave them like that

I checked my moderation log and none of my mods or staff did this. There must be a hole in RC3

1.  Aeva ~ Auto-Embed Video & Audio  7.0    May 09, 2010, 01:15:17 PM  [ Uninstall ]  [ List Files ]  [ Delete ]
2. Change Report Text To Image 1.0 April 13, 2010, 06:49:15 AM [ Uninstall ] [ List Files ] [ Delete ]
3. Contact Page 2.0.1 April 12, 2010, 10:21:56 PM [ Uninstall ] [ List Files ] [ Delete ]
4. Country Flags 1.1.1 April 14, 2010, 04:29:57 PM [ Uninstall ] [ List Files ] [ Delete ]
5. CSS Message Boxes 1.1 June 14, 2010, 08:50:26 AM [ Uninstall ] [ List Files ] [ Delete ]
6. Current Signature Mod 1.1 May 19, 2010, 08:55:34 PM [ Uninstall ] [ List Files ] [ Delete ]
7. Join date and Location in Posts 1.0 June 14, 2010, 08:54:04 AM [ Uninstall ] [ List Files ] [ Delete ]
8. MetaTags Modification 1.4 April 14, 2010, 04:29:27 PM [ Uninstall ] [ List Files ] [ Delete ]
9. PM Sent Notification 1.0.4 May 09, 2010, 01:34:09 PM [ Uninstall ] [ List Files ] [ Delete ]
10. reCAPTCHA for SMF 0.9.8 June 20, 2010, 09:06:47 AM [ Uninstall ] [ List Files ] [ Delete ]
11. Register At Post View v.1.1 1.1 June 14, 2010, 08:45:36 AM [ Uninstall ] [ List Files ] [ Delete ]
12. Signature Dropdown Choices 1.2 May 08, 2010, 07:21:09 PM [ Uninstall ] [ List Files ] [ Delete ]
13. Sitemap 2.1.2 April 14, 2010, 04:25:15 PM [ Uninstall ] [ List Files ] [ Delete ]
14. Sortable Packages (and Installed Time) 1.3 April 13, 2010, 09:21:45 AM [ Uninstall ] [ List Files ] [ Delete ]
15. Team Page 3.5.4 April 12, 2010, 06:53:27 PM [ Uninstall ] [ List Files ] [ Delete ]
16. TinyPortal 1.099 April 12, 2010, 04:02:37 PM [ Uninstall ] [ List Files ] [ Delete ]
17. Users Online Today 1.5.6 April 14, 2010, 04:26:23 PM [ Uninstall ] [ List Files ] [ Delete ]
18. Wibiya Integration Mod 1.1 May 08, 2010, 03:05:15 PM [ List Files ] [ Delete ]
19. WYSIWYG Quick Reply v2 RC3 April 14, 2010, 04:12:16 PM [ Uninstall ] [ List Files ] [ Delete ]

~DS~

"There is no god, and that's the simple truth. If every trace of any single religion were wiped out and nothing were passed on, it would never be created exactly that way again. There might be some other nonsense in its place, but not that exact nonsense. If all of science were wiped out, it would still be true and someone would find a way to figure it all out again."
~Penn Jillette – God, NO! – 2011

Forbs


SN

Im looking through my forum now to see if anything else has changed.

Nothing has changed... it was just my Boards and sub-boards names and that was it.

How the hell have they done that?

SN

Quote from: Forbs on July 26, 2010, 03:57:42 AM
Your forum is hacked :D

This is a useful post... really worth smiling about huh?

~DS~

Quote from: Forbs on July 26, 2010, 03:57:42 AM
Your forum is hacked :D
You would like me to email the hacker to hack yours?  ::)
"There is no god, and that's the simple truth. If every trace of any single religion were wiped out and nothing were passed on, it would never be created exactly that way again. There might be some other nonsense in its place, but not that exact nonsense. If all of science were wiped out, it would still be true and someone would find a way to figure it all out again."
~Penn Jillette – God, NO! – 2011

SN

anybody know how i can prevent this from happening again?

~DS~

Quote from: SN on July 26, 2010, 04:11:19 AM
anybody know how i can prevent this from happening again?
I suggest you backup the files and the database before it happen again.
Any errors in the logs?
"There is no god, and that's the simple truth. If every trace of any single religion were wiped out and nothing were passed on, it would never be created exactly that way again. There might be some other nonsense in its place, but not that exact nonsense. If all of science were wiped out, it would still be true and someone would find a way to figure it all out again."
~Penn Jillette – God, NO! – 2011

SN

Quote from: Delita on July 26, 2010, 04:14:40 AM
Quote from: SN on July 26, 2010, 04:11:19 AM
anybody know how i can prevent this from happening again?
I suggest you backup the files and the database before it happen again.
Any errors in the logs?

No errors in log.

I have back ups every day... i have crons set up.

But, this has to be some kind of security hole within SMF RC3. So this could happen to anybody i think

CapadY

Are you sure there is nobody with acces to the admin panel of your host ?

This can also be done with a very simple MySQL query in PHPMyAdmin. That way you will never find it back in the logs.
Maybe an idea to change your password at your host ?
Please, don't PM me for support unless invited.
If you don't understand this, you will be blacklisted.

SN

Quote from: capady on July 26, 2010, 05:02:53 AM
Are you sure there is nobody with acces to the admin panel of your host ?

This can also be done with a very simple MySQL query in PHPMyAdmin. That way you will never find it back in the logs.
Maybe an idea to change your password at your host ?

Ok i will change my host password. But nobody else has access to that only me


Advertisement: