URGENT - ( yes I have ) BEEN HACKED - NEED HELP

Started by DevinL, January 04, 2012, 05:09:09 PM

Previous topic - Next topic

DevinL

I think.

Every thing I click on, on my forum is trying to redirect me to:

"http://www.opsofo.com/index.php?PHPSESSID=hikgufeu07mcqo57i09q8fm9s1;wwwRedirect"

I'll worry about how after, but I need to get rid of this ASAP, where is this coming from?
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Illori

that is not a hacking, it is a phpsession id added to your url along with a wwwredirect. which neither are hacking related your forum is fine.

DevinL

OK thanks. Just so I understand, this is happening how, from my browser?
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Illori

if your browser correctly accepted the cookie the phpsession id should not appear in the address bar.

DevinL

Sorry if I'm pissing people off with my ignorance here. This problem doesn't seem to be browser related. I have tried from 2 different computers now, and from my phone connected over the cell net (not wifi). I'm getting the same thing on all three devices so I don't understand where this is coming from if not from the site.
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Illori

it is part of how smf works, it is not related to hacking

DevinL

Ok I get that its not hacking Illori. I have changed the post title. Can you or someone please tell me where to start looking or working to rectify this problem.
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

MrPhil

If your browser is not configured to accept cookies, you'll get that session ID past the first page or two (once you sign in). If your browser is configured to allow cookies, you may have some sort of configuration problem. Try clearing your browser cache and your SMF-specific cookie(s), and search for other postings discussing this problem (IIRC one solution is to change the cookie name in SMF's configuration in Settings.php).

DevinL

Thank you MrPhil. I have cleared my cookies and checked to make sure it's accepting cookies. This is happening across 3 different devices, so to my way of thinking something has changed on the server side of things.  The only thing I changed was was to add google analytics script (which was working fine) and to add the sitemap mod. The forum tested out fine after both those installs.
I'm sure I haven't changed anything else.
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

DevinL

Sorry if I'm coming across pissy to you guys, its not intended to be that way. I'm just very frustrated with this. I'm new to this, and don't have the kind of experience and understanding you guys have.
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Chen Zhen

Quote from: DevinL on January 04, 2012, 08:06:47 PM
Thank you MrPhil. I have cleared my cookies and checked to make sure it's accepting cookies. This is happening across 3 different devices, so to my way of thinking something has changed on the server side of things.  The only thing I changed was was to add google analytics script (which was working fine) and to add the sitemap mod. The forum tested out fine after both those installs.
I'm sure I haven't changed anything else.

looked at your site  and imo some kind of javascript conflict with that google anyalytics mod.

Manually typing in regular url's works fine.
Do you have one of the mods installed that changes url's like Simple SEF or maybe Pretty Url's?
Try disabling/uninstalling it for a test.

My SMF Mods & Plug-Ins

WebDev

"Either you repeat the same conventional doctrines everybody is saying, or else you say something true, and it will sound like it's from Neptune." - Noam Chomsky

DevinL

Thank you Underdog. I do have pretty url installed.

I'll pull the google code and see if that helps
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

mashby

I'd uninstall prettyURLs. They aren't doing much for you. The Google code is more valuable.
Always be a little kinder than necessary.
- James M. Barrie

DevinL

Ok, the question then I have now is how? I cant log into my admin panel with the redirect problem. Or am I better to just lose the google code for now, and reinstall after I ditch pretty urls?
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Chen Zhen

Quote from: DevinL on January 04, 2012, 08:28:59 PM
Ok, the question then I have now is how? I cant log into my admin panel with the redirect problem. Or am I better to just lose the google code for now, and reinstall after I ditch pretty urls?

Navigate directly to this url: http://www.opsofo.com/index.php?action=admin;area=packages;

My SMF Mods & Plug-Ins

WebDev

"Either you repeat the same conventional doctrines everybody is saying, or else you say something true, and it will sound like it's from Neptune." - Noam Chomsky

DevinL

Quote from: -Underdog- on January 04, 2012, 08:33:11 PM
Quote from: DevinL on January 04, 2012, 08:28:59 PM
Ok, the question then I have now is how? I cant log into my admin panel with the redirect problem. Or am I better to just lose the google code for now, and reinstall after I ditch pretty urls?

Navigate directly to this url: http://www.opsofo.com/index.php?action=admin;area=packages;

Thanks I did manage to figure that part out, but I get trapped at the password login. Can I pass login information in the url as well?
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Chen Zhen

Quote from: DevinL on January 04, 2012, 08:40:26 PM
Thanks I did manage to figure that part out, but I get trapped at the password login. Can I pass login information in the url as well?

No.
Perhaps the repair settings tool is in order?

Read this: http://docs.simplemachines.org/index.php?topic=663.0

.. or your other option is to use the large upgrade package which will replace all SMF files with defaults.


My SMF Mods & Plug-Ins

WebDev

"Either you repeat the same conventional doctrines everybody is saying, or else you say something true, and it will sound like it's from Neptune." - Noam Chomsky

DevinL

Just remembered, I never got the google code to work, and installed http://custom.simplemachines.org/mods/index.php?mod=2210 to get it going. Could this be the offending party?
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Chen Zhen


Did you manually add some code somewhere?
Like some sort of Bing Analytics script?

My SMF Mods & Plug-Ins

WebDev

"Either you repeat the same conventional doctrines everybody is saying, or else you say something true, and it will sound like it's from Neptune." - Noam Chomsky

DevinL

No I haven't added any code. I did originality add the Google analytics code, but it didn't work properly so I removed it. I know I rechecked that everything was working after I removed the code and everything was fine. The more I think about it, I'm sure its that mod I used that I mentioned above. I'm sure I forgot to recheck the forums after I installed it. I just remember being happy that Google gave me the thumbs up for being able to do the analytics, and completely forgot to make sure the forums were still functional. Damn it!
Proud owner of OPSOFO - the OPen SOurce FOrums
REAL IDEAS FROM REAL PEOPLE FOR REAL PEOPLE

Advertisement: