Account breached! Urgent

Started by xyxis_fahim, July 08, 2008, 11:06:08 PM

Previous topic - Next topic

xyxis_fahim

Hello,
So strange to see my main account password and email was changed to  [email protected] . Possibly an hacker? I googled that email but found only 1 result.

Has anyone know about this? I'm under fear.

Bigguy

Are their any errors in the error logs in the admin control panel or in the error logs in cpanel. ???

xyxis_fahim

From Cpanel error log:

[Tue Jul 08 22:09:19 2008] [error] [client xx_IP_xxx] client denied by server configuration: /home/truforum/public_html/attachments/g.php

thats all

Bigguy

Not sure what happened then. Do you have other admins on your forum. ???

xyxis_fahim

Yes one other, my good friend.  He didn't change any settings he said.

H

-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

karlbenson

Are you running smf 1.1.5?

If not upgrade asap!

metallica48423

also -- i'm assuming that you're not encrypting attachment filenames? If you are not, you want to block common script file types or someone with ill intention may be able to run arbitrary code on your site.
Justin O'Leary
Ex-Project Manager
Ex-Lead Support Specialist

QuoteMicrosoft wants us to "Imagine life without walls"...
I say, "If there are no walls, who needs Windows?"


Useful Links:
Online Manual!
How to Help us Help you
Search
Settings Repair Tool

knaphih

I must say....always keep a backup ready for such incidences...ive had this prob around a year back on my first smf forum.. It was an admin who played with the things...

Bigguy


xyxis_fahim

Quote from: Bigguy on August 20, 2008, 05:47:23 PM
Hows things going now xyxis_fahim ???
Never mind , it was a host issue. You may delete this topic. Thanks.

joshuam08

Just To Add Make Sure You Encrypt Attachment Names So People Cannot Run Script
Gamingguru.org Admin
http:\\www.gamingguru.org

Advertisement: