News:

Wondering if this will always be free?  See why free is better.

Main Menu

My site was hacked twice this day

Started by real1, March 25, 2010, 12:51:48 PM

Previous topic - Next topic

real1

Hi i have this website with smf forum:

http://aikidoportugal.net/forum/

Yesterday it got hacked, so i checked all different files in the /forum folder, and updated to 2.0 rc3 version hopping it will be safe for good. So today i get to work, and checked my forum and there it was again. If you check my link you'll see who it is.

What do you advise me, what more can i delete or can i block all ips from that country, if so what is the best way to do it and how? Please.

Is there any security mod, or ban country module or something? Is it possible that he left some files i dont know, and defaced again, because he sent bogus files to my forum root, wich i deleted.

Once again thank you very much for your help.

Kays

Hi, just deleting files won't stop him/her. You need to figure out how access is being gained and to stop that.

Please read and follow all suggestion. Also ensure that any others with admin access do the same.

How do I make my forum safer against hacker attacks?

If at first you don't succeed, use a bigger hammer. If that fails, read the manual.
My Mods

Jakob Fel

#2
Wow, when I went to your site, it said *****..! Weird.
Freelance writer and advocate for security, privacy & DRM-free distribution
Support and Community Management at SMFNew Free Forum Hosting

Kays

It's not a good idea to post that name. They use the Google hits on their name to get an indication of success and for bragging rights.

If at first you don't succeed, use a bigger hammer. If that fails, read the manual.
My Mods

real1

Hi, Kays, ill try that later at home. Thanks. If someone has any other ideas, they are welcome. And do delete his name, thats why i didnt posted.

Kays

I removed the name and good luck with this.

If at first you don't succeed, use a bigger hammer. If that fails, read the manual.
My Mods

Bloodsurfer

FYI: ATM the site is defaced again.

Is this only webhosting or a real server? If it is a server, you should delete and completely reinstall it from scratch, not only delete "bad" files.

Even if it is only a hosted webspace - best is to make a database dump, delete _all_ files, set up a fresh forum with the old database, then change _all_ passwords.

Jakob Fel

Quote from: Kays on March 25, 2010, 01:21:28 PM
It's not a good idea to post that name. They use the Google hits on their name to get an indication of success and for bragging rights.

I have no clue what you mean.
Freelance writer and advocate for security, privacy & DRM-free distribution
Support and Community Management at SMFNew Free Forum Hosting

Kays

Hackers rate how successful they are by counting the Google hits on their signature, which they leave on a hacked page. By posting that, you've possibly added another hit to someone's tally.

So it's good practice not to post something like that.

If at first you don't succeed, use a bigger hammer. If that fails, read the manual.
My Mods

tumbleweed

The op needs to look for some shell (c99.php) scripts in his webspace. If he does not find any it is possible that the server itself has been compromised and contact your host if you are on shared hosting. And really its hard to tell what is going on with the OP maybe he is running outdated programs of another sorts.

What the defacers do is goggle there name and it brings up all the sites they have defaced. Then they head over to there hacking forum and brag to there friends how many sites they have hacked.
G.C. SOLUTIONS - Hosting Quality Sites Since 2006. Experience Your Forums On A Whole New Level
Elastic Sites Stress Fast CPU/Ram Upgrades- More Info Here.
Reviews By SMF Forum Owners - Read Our Rev

Jakob Fel

Freelance writer and advocate for security, privacy & DRM-free distribution
Support and Community Management at SMFNew Free Forum Hosting

tumbleweed

When I get back home. I will post up a cool site that keeps track of defacers like this one.

Frank
G.C. SOLUTIONS - Hosting Quality Sites Since 2006. Experience Your Forums On A Whole New Level
Elastic Sites Stress Fast CPU/Ram Upgrades- More Info Here.
Reviews By SMF Forum Owners - Read Our Rev

Road Rash Jr.

Quote from: tumbleweed on March 25, 2010, 03:57:50 PM
When I get back home. I will post up a cool site that keeps track of defacers like this one.

Frank

Hey Frank did you find that link?
Never argue with an Idiot like myself, they just drag you down to their level then beat you with experience.

tumbleweed

G.C. SOLUTIONS - Hosting Quality Sites Since 2006. Experience Your Forums On A Whole New Level
Elastic Sites Stress Fast CPU/Ram Upgrades- More Info Here.
Reviews By SMF Forum Owners - Read Our Rev

Norv

hello, was this problem solved or do you require more assistance with this?
To-do lists are for deferral. The more things you write down the later they're done... until you have 100s of lists of things you don't do.

File a security report | Developers' Blog | Bug Tracker


Also known as Norv on D* | Norv N. on G+ | Norv on Github

flapjack

hi OP, can you please let us know what sort of ftp software you are using?

Advertisement: