Site is being hacked as we speak

Started by Kimmie, November 17, 2013, 01:56:01 PM

Previous topic - Next topic

Kimmie

Yeah I looked at htaccess and though it looked really weird and was going to be the next thing I had you look at ;)


Kindred

from this, I assume that your site is patriotgames2.info?

if so, I don't see anything wrong with that file
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Kimmie

yes - I have it in main mode now, but I can turn that off so you can see what they did

kat

I wonder...

ipntreas.php makes me think there's a FlashChat installation, on-site.

Just how secure is that thing?

Kimmie

ok I turned the site back on... go check it out

Kimmie

Quote from: K@ on December 26, 2013, 12:08:18 PM
I wonder...

ipntreas.php makes me think there's a FlashChat installation, on-site.

Just how secure is that thing?

The date on that file is 5/16/2013. Not sure what it is.

Kimmie

Its legit...Its from my treasury mod



Illori

<div class="sp_content_padding">
<a href="http://patriotgames2.info/index.php?PHPSESSID=513ae9ad34237af91233a17f9ffd8530&amp;action=profile;u=1"><img src="http://patriotgames2.info/avatars/Various/misc11.gif" alt="kjb0007" width="30" class="sp_float_right" /></a>
<div class="middletext">December 22, 2013, 12:32:44 PM by <a href="http://patriotgames2.info/index.php?PHPSESSID=513ae9ad34237af91233a17f9ffd8530&amp;action=profile;u=1" style="color: #99CCFF;">kjb0007</a><br />Views: 44 | Comments: 8</div>
<div class="post"><hr /><head><link href=http://getpremiumminecraft.com/font/sa3ek/InG.css &nbsp;type=text/css rel=stylesheet></head></div>


that seems to be causing part of your issue.

Kindred

looks like something was added ot the end of index.php or index.template.php
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Kimmie

Quote from: Illori on December 26, 2013, 12:18:45 PM
<div class="sp_content_padding">
<a href="http://patriotgames2.info/index.php?PHPSESSID=513ae9ad34237af91233a17f9ffd8530&amp;action=profile;u=1"><img src="http://patriotgames2.info/avatars/Various/misc11.gif" alt="kjb0007" width="30" class="sp_float_right" /></a>
<div class="middletext">December 22, 2013, 12:32:44 PM by <a href="http://patriotgames2.info/index.php?PHPSESSID=513ae9ad34237af91233a17f9ffd8530&amp;action=profile;u=1" style="color: #99CCFF;">kjb0007</a><br />Views: 44 | Comments: 8</div>
<div class="post"><hr /><head><link href=http://getpremiumminecraft.com/font/sa3ek/InG.css &nbsp;type=text/css rel=stylesheet></head></div>


that seems to be causing part of your issue.


That is the av I use on the site  (kjb is me)


Kimmie

Quote from: Kindred on December 26, 2013, 12:23:10 PM
looks like something was added ot the end of index.php or index.template.php

Index.php from inside root is attached

Kindred

so.. not there...

Rather than throwing out suggestions, one by one, your host really needs to do a SERVER scan for matching strings and recently added files --- as well as look at the server logs form 3AM onward.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Kimmie

Yeah I gave them the time frame it happened in and told them they had 12 hours to figure out what the heck happened and get it resolved or I was looking for a new host.

In the meantime.. I have a publichtml backup from Dec 1st. In lamens terms (hehe), give me the steps I need to do to rectify this on my end. What would "you"do?


Illori

if you look at http://patriotgames2.info/index.php?topic=85549.0 the code i posted above is in that topic in the first post it seems

Kimmie

Quote from: Illori on December 26, 2013, 12:36:22 PM
if you look at http://patriotgames2.info/index.php?topic=85549.0 the code i posted above is in that topic in the first post it seems

Should I go into the DB and delete that thread?

Illori

http://patriotgames2.info/index.php?action=post;msg=256089;topic=85549.0

see if that works to modify the post and remove the call to the css in the head tag

Kimmie

Quote from: Illori on December 26, 2013, 12:45:53 PM
http://patriotgames2.info/index.php?action=post;msg=256089;topic=85549.0

see if that works to modify the post and remove the call to the css in the head tag



I am a semi-noobie.. what does that mean?  :/

Illori

can you click the link? can you remove the content of the post that includes a <head> tag and the link to the css i quoted before?

Kimmie

Quote from: Illori on December 26, 2013, 12:50:24 PM
can you click the link? can you remove the content of the post that includes a <head> tag and the link to the css i quoted before?


When I clicked the link you give me, all I see is that big purple image not the actual post itself so I cannot do any editing on that front.

In the DB when I edit that post, this is what I get. Is there something here I can change?


Advertisement: