Update concern, HACKS and databases not working!!! incompability

Started by Nitro, August 03, 2005, 12:27:35 PM

Previous topic - Next topic

Nitro

i am not prejudging your hard work guys, i know you have done an excellent work but i think there is something wrong in this new SMF and the installer.

well, this is really bad, i think there is a bug in this SMF software because it allows someone to modify your template. recently my site was HACKED! somehow this person managed to get a BIG message in the main index page, something about this copy is not good and it is important you contact smf for a iligal copy! in my index file the right code for showing the copyright was still there. so there is a security hole somewhere.

now the BIG problem is, when you try to run the installation AFTER a crash again, it kicks an error that i am using an old database structure! WHY? i have been already using the new SMF for awhile, i don't think this should happen. regardless if we shoud've made a back up or not of our database becuase you get so carried away with this new forum and stuff, so i think still when you install again the install should be able to recognize you have anew structure or what? no matter what SMF version you install, if it's old it says it is new and if you install the new one, upigrade by upgrade, it tells you you have an OLD database structure, now i am screwed! i have tons of valueble information that my 1,800 members need.

perhaps i am the only one here and i am just very upset about this HACKING deal, that i can't seem to find the answer.

why the installer gives you this error? saying yuou are using an old database WHEN you HAD a previous NEW SMF version?

this is a BAD BUG!!

any comments, are you experiencing that
MPF Rocks!!!

Nitro

sorry i forgot!
wouldn't be a good idea you guys create boards or child board for specific errors or MAJOR errors, for example you have the installation section, well, why not creating child board about major specifi problems about installation? it's a pain looking everywhere for the answer when you are in an emergincy like my site when it was HACKED somehow?

MPF Rocks!!!

Kindred

hmmm.... what evidence do you have that your site was hacked?

That "illegal copy" message is a standard part of SMF, it's not a hack.

And you should have deleted your install.php file after installation, otherwise is IS a security hole (of your own making)

How about giving us a URL to take a look at?
(PM me if you don't want it public)
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Nitro

do you i am messing around with this stuff after all the awesome support i have always received? come on! well, i don't know about this stuff but, how am i gonig to prove it was hack? simple, it was late last night and i decided to take a last peek at what others were doing around and i found this message, i didn't do it i have been very happy with the SMF! thank you very much!
and about a link sure, i don't care if someone visits the site, www.mypowerforum.com/bb take a quick peek but get this, i have contacted my host and i told them about the time i think the site was changed so there is only one way to make changes and that is ftp, so i asked them to give me any IP address because i have only one static IP address so i know if i see something diferent, there! i will have my prove!

what a grief! maybe you have done that before and you acuse me of removing the copy rights huh? byu the way, there is no install php there, it was deleted it right after the updgrade LONG time ago.
MPF Rocks!!!

Kindred

Nitro... I'm not really trying to give you grief.

I notice that you are (sort of) using the mambo bridge and that your problems happened after you installed the "redirect" code.   I think you may have altered something with that code-change (by accident) which caused the copyright issues...
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

1MileCrash

This is NOT a hack. Think about it, what kind of moron would hack your forums and remove your copyright? Just upload a new Sources.php, and see if that fixes it.
The only thing php can't do is tell you how much milk is left in the fridge.



Nitro

well, everything was working fine with the mambo bridge. no one has access to the admin page or the ftp but me. so, how in the world this could come up? i had to reinstall everything but now, i have  peculiar error when i am doing either installation or update. so, i think someone really hacked my site! there is no way this could be messed unless the person who has access to the admin or the ftp has done it.

so, i have mad changes but that is to the mambo bridge through the admin, but these things are like publishing and nothing else, and how funny the message was only in the forum footer? so this really tells me someone found a hole in the code and messed it up!

oh i didn't installed the code i was told for the redirect thing. i left everything like it was before and that was line #2
MPF Rocks!!!

Kindred

Nitro...

I don't think ther eis any hole in the SMF or mambo integrated code...
I have been running both on my site for as long as the integration has existed...

In cases like this, it is most likely due to some error on the part of the admin, especially in updating the code.
What editor did you use to do your code update and upload via FTP?

(I ask this because Dreamweaver and microsoft notepad/wordpad have been known to mess up php files...)

There are three causes of that copyright notice happening.
1- the footer in index.template.php is messed up somehow (either on purpose of by accident, the copyright call is removed/altered)
2- Subs.php is corrupted, causing the copyright warning to appear.
3- Your language files are corrupted, meaning the copuright text is incorrect...

These are, essentially the only things that will cause the error you describe.
It is unlikely that a hacker got into your site and did only that.
It is much more likely that something you did (accidnetally, of course) corrupted or changed on of those files...

The quick and easy fix is to upload a fresh copy of the entire forum, run repair_settings.php and re-apply your mods & themes...
(your database should be just fine and you do not need to run install.php again!)

Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Nitro

well, if you have not ran into hackers in your site, then you are lucky. i have never had this problem before.
i use smartFTP 1.1 and it has worked great for me.

as far the hacker i belelieve it, and for the accidents may happens like this or that file got messed up, well you might be right about that.

botttom line is i didn't mess with the copy right thing and in my forum no one has access to the admin page.

i think it is hard to say and you might be right about this accident thing. i do modify things to accomodate personal information from my members but there is only profile and register php files i have messed with. i have added some fields newmembers must have and that's it. so i don't mess with the index.php which at the end that is where the problem was. i uploaded a new index.php and that fixed the problem but with all the things i moved and uploaded things got even more messed up tryiing to follow tips from others, not that i am blaming on them, in fact, i appreciate those tips people tell me. i think moving things around is how i finally came to realize doing something else to perhaps fix the problem and that did the trick! so, without their comments i would be still sitting here waiting for something else to happen.

i treid repair setting and that also didn't fix the problem, well the hack is gone but there came another problems after the mess.

thank you guys!
MPF Rocks!!!

Advertisement: