News:

SMF 2.1.4 has been released! Take it for a spin! Read more.

Main Menu

I was hacked

Started by kcmagicdata, July 29, 2008, 07:18:10 PM

Previous topic - Next topic

kcmagicdata

I was hacked today by

"HACKED By 3RqU "

Not that they did anything other than "Tag" me  with a index.htm file .It also added a new Adminsitrator account to my forum.
I am using ver 1.1.1 and am currently having alot of trouble getting any of the updates to go through. Everything i try results in error this error that unable to this unable to that. Is there anything else i should check for?




*removed the hackers link

Delidereli

smf 1.1.5 e geç gardaş. 1.1.4 te sql injection açığı var

ccbtimewiz

#2
I'm afraid some idiots found a hole in SMF 1.1.4 that allows them to use SQL injections to alter their permission levels.

The fix for this is to update to SMF 1.1.5. There are no other options.

hypercube

Please help me. I have also been hacked by some EFSANE87 guy and I cant seem to fix this problem. He created an admin account wich I now deleted using my database webadmin, but still it keeps showing "Hacked by...". Is there any way to hack it back so I can keep all posts and stuff?

Thanks in advance,

Hyper

Tony Reid

Where does it say hacked by?

May we have a link please.

Tony Reid

hypercube

when I go to the forum it says that. So I thought lets try just manually typing in boards or the admin panel, but it keeps showing the message. I changed the directory to something else now, but I'll change it back for a sec. Tell me when you viewed it: http://www.wshadows.com/forum

Tony Reid

Check your default language files for suspicious stuff - index

You can login using imode : http://www.whiteshadowsclan.com/forum/index.php?action=login;imode

Tony Reid

hypercube

#7
Quote from: Tony on August 01, 2008, 05:41:37 AM
Check your default language files for suspicious stuff - index

wich files are those exactly? And are you trying to say that the database is still "good"? Cause all boards and stuff are there.
Btw thanks for that imode thing! Didnt know about that.

Tony Reid

Have you many mods installed?

Your language files are here :

/forum/Themes/default/languages

check index.english.php


Tony Reid

hypercube

yeah I got about 5-6 mods installed.

I'll put the file here, didnt find anything strange in it.

Tony Reid

ok what about your Settings.php file? (please dont upload it - its got your db password in!)
Tony Reid

hypercube

nothing..
Should I try downloading a new smf 1.1.4 package and then upload it in place? Then we know if its the database or any files...

Tony Reid

rename the default theme directory to default_bak

And then just reupload the default theme from a fresh download here.

Its not your DB.
Tony Reid

hypercube

i cant find a smf 1.1.4 download, still looking.. :/

Tony Reid

use a 1.1.5 for the moment.

Tony Reid

hypercube

I accidently deleted the database (i backed it up though). So now im trying to restore that first with phpmyadmin. But its giving some errors atm.

hypercube

ok i solved some strange things.. look now.
there are no picture but posts are back :/

Tony Reid

Now switch your default theme back to colatesi_v3 in the admin cp

Is this it?

http://www.whiteshadowsclan.com/forum/index.php?theme=2
Tony Reid

Tony Reid

I see its all done.

You really need to upgrade to 1.1.5 - this can be done in your admin cp under packages.

Tony Reid

hypercube

Quote from: Tony on August 01, 2008, 07:26:47 AM
Now switch your default theme back to colatesi_v3 in the admin cp

Is this it?

http://www.whiteshadowsclan.com/forum/index.php?theme=2

ok how the hell did u know it was called like that and how did that theme land up there :S

Its working again now btw, I dunno what I did :P

Thanks so much, I dont know how to tell you how much u helped me. You're the best!



If I upgrade it cant be hacked again?

Advertisement: