Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Hack Attempt Script
Author Message
yonkersking
New Member
New Member


Joined: Aug 30, 2006
Posts: 8

PostPosted: Thu Aug 31, 2006 12:16 pm Reply with quote

My index.php file has been hacked 2 days in a row now Confused . Thank god, I had made a backup of all major files. How can I stop this from happening again?
 
View user's profile Send private message
Tao_Man
Involved
Involved


Joined: Jul 15, 2004
Posts: 252
Location: OKC, OK

PostPosted: Thu Aug 31, 2006 1:27 pm Reply with quote

I would say install Raven Nuke 2.02.02 and newest version of Nuke Sentinel.

What are you running? Nuke? What version? Wo you have sentinel installed? What version?

Need more info....and if you got the hack in your web logs that would help also.

_________________
------------------------------------------
To strive, to seek, to find, but not to yield!
I don't know Kara-te but I do know cra-zy, and I WILL use it! 
View user's profile Send private message Visit poster's website
yonkersking
PostPosted: Thu Aug 31, 2006 3:16 pm Reply with quote

I use the newest Raven 7.6 nuke. I got it off this site about 2 months ago.
 
Tao_Man
PostPosted: Thu Aug 31, 2006 3:27 pm Reply with quote

Well you may need to update Sentinel, but without some logs to go by it is next to impossable to say how they got in and what you can do to make sure it does not hapen again.

Nothing is 100% hack proof, Raven's is about as good as it gets for Nuke security, there are other forks/mods that are good I will not play favorite and say one is the best but you arn't going to get much better then you have with Raven Nuke and newest Sentinel installed.

Try and dig through your logs, almost all hack attemps will leave some traces behind that can be put together to come up with some way to avoide them.
 
yonkersking
PostPosted: Thu Aug 31, 2006 5:03 pm Reply with quote

You think it could be my settings for sentinel? What are the correct settings for sentinel to fully secure your website?
 
jaded
Theme Guru


Joined: Nov 01, 2003
Posts: 1006

PostPosted: Fri Sep 01, 2006 8:31 am Reply with quote

what is your version of sentinel? the one included in rn is not the latest as many releases have come out recently. Also, what addons are you using? What is your sites url? Are you using anything that allows upload on your site? Are you using a gallery? Are you using any clan based addons like VWAR or anything? Are your forums up to date? Have you ever upgraded them? Look on the main forums admin page for your current version it will be listed in red. Click on Sentinel and read the version number at the top of the next page. We really cannot help without more information. Good Luck!

_________________
Themes BB Skins Only registered users can see links on this board! Get registered or login!
Graphic Tees Only registered users can see links on this board! Get registered or login!
Paranormal Tees Only registered users can see links on this board! Get registered or login!
Ghost Stories & More Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
technocrat
Life Cycles Becoming CPU Cycles


Joined: Jul 07, 2005
Posts: 511

PostPosted: Fri Sep 01, 2006 10:16 am Reply with quote

There is a chance (a big chance) that upgrading sentinel will not stop the attacks. The reason I say this is because you have files that were changed. It depends on what hack they are using. Currently the most common one is the phpbb attack. Upgrading sentinel WILL block this.

Though if you have vWar, coppermine, spchat, or any other known hackable modules then sentinel WILL NOT stop these attacks.

Also a VERY common attack right now is the php 777 attack. If this is the attack then there is really nothing sentinel will do to help you. You need to adjust your folder security settings or move hosts.

The final attack could be they have hacked your FTP or web server. With these attacks the only way to prevent them is to change passwords or hosts. Though more than likely this is not the hack used because they would probably be deleting your site.

_________________
Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! / Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message
yonkersking
PostPosted: Fri Sep 01, 2006 10:26 am Reply with quote

I do not have any of the modules stated. I use a few others though. Like the donations module, 4n chat, guessing game, nuke television, nukec classifieds module, all the rest are either from this site or nukescripts. Also I do not have the forums active. Would that make a difference from someone entering that way?
 
jaded
PostPosted: Fri Sep 01, 2006 10:30 am Reply with quote

it might help if you could answer some of the specific questions that I asked you. it makes it easier for us to help you.
 
yonkersking
PostPosted: Fri Sep 01, 2006 7:34 pm Reply with quote

I use NukeSentinel(tm) 2.4.2pl5. I do not allow anything to be uploaded. The forums are not in use and disabled. I am running running phpBB 2.0.20. Should it still be updated? No gallery of any type. I have a calender module ( KalenderMx 1.4.c ), MS_Analysis v2.2 Pro, I have the helpdesk from disipal.net, PHP-Nuke Syndicated News Version 1.0.0, Guessing Gamemod, Donation mod and the Weather mod from nukescripts. I did have other modules but they were not being used and I removed them. My website is Only registered users can see links on this board! Get registered or login!
 
FireATST
RavenNuke(tm) Development Team


Joined: Jun 12, 2004
Posts: 637
Location: Ohio

PostPosted: Sat Sep 02, 2006 11:20 am Reply with quote

That is not the latest NukeSentinel. It has been upgraded several times since then. It is now up to 2.5.02 if I remember correctly. When you install programs such as these, you need to check back from time to time to see if they have been updated, since holes are discovered frequently, so you are able to protect your site the best you can.... Very Happy
 
View user's profile Send private message Visit poster's website MSN Messenger ICQ Number
technocrat
PostPosted: Sat Sep 02, 2006 11:56 am Reply with quote

If I remember correctly 2.4.2pl5 did have the phpbb catch in it. So if that is true then my next guess would be the php 777 attack. Do you have folders that were CHMOD to 777?
 
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3191
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Sat Sep 02, 2006 12:34 pm Reply with quote

You need to activate HTTP Auth.


There is also a new version for the calendar out KalenderMx 1.4.d I would update this because several older versions of calendars have a security problem. The author said XSS attacks in older versions but how knows...

Btw: Name of the hacker ?
 
View user's profile Send private message
yonkersking
PostPosted: Sat Sep 02, 2006 12:58 pm Reply with quote

Thank you for the info. When you upgrade, do you have to go threw the next version. Or can you go striaght to newest?

One hack was dr.jr7 ( France Ip ). The second was Dengeniz from Jordan.

Someone built the website for me. My knowledge of php is mid range. So I image I will spend alot of time here.
 
yonkersking
PostPosted: Sat Sep 02, 2006 1:13 pm Reply with quote

Also as far as my knowledge KalenderMx 1.4.d is the latest version. Do you think I should remove it? Also if yes, do you know a secure program like it?
 
Susann
PostPosted: Sat Sep 02, 2006 3:37 pm Reply with quote

If it was this group: Only registered users can see links on this board! Get registered or login!

you need to check all files to find out if there are new unknown files or folder.

As I know from other guys they use different IPs also from Asia.
You really need to find out how they hacked the website.Check your logfiles, nukesentinel and possible ask your webhoster.
For the calendar I only meant its a good idea to upgrade this also because there is e.g. some new anti-spam protection included. I don´t use and don´t need any calendar.
To upgrade NukeSentinel go to nukescripts.net and download NS 2.5.00 and download also the neweste 2.5.02.
 
hitwalker
Sells PC To Pay For Divorce


Joined:
Posts: 5661

PostPosted: Sat Sep 02, 2006 5:20 pm Reply with quote

well you dont simply alter a root file,they have to get the access and permissions from somewhere..
 
View user's profile Send private message
yonkersking
PostPosted: Sat Sep 02, 2006 5:22 pm Reply with quote

I'd much rather ban alot of countries ip ranges. My site gets alot of hits from all over the world. Although the hits are great. I'd much rather block ip's from middle east, Germany, China, Japan, France and countries like that. How can that be done?

Ps: Thanks for all the help.
 
hitwalker
PostPosted: Sat Sep 02, 2006 5:40 pm Reply with quote

ok here is what the doctor describes.... Twisted Evil

put this in your htaccess..

that didnt worked...
 
hitwalker
PostPosted: Sat Sep 02, 2006 5:42 pm Reply with quote

pm me your email address..
ill send htaccess ban list..
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Hack Attempt Script

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©