Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 7.6
Author Message
mrix
Client



Joined: Dec 04, 2004
Posts: 757

PostPosted: Tue Apr 04, 2006 10:57 am Reply with quote

Hello all, two of my sites were hacked today and left this message

Defaced By D.O.M
domteam.info

HEy Just Remember Jesus Love You!

I have everything up to date as far as I know and havnt been hacked in over a year now

any idea`s

Cheers
mrix
 
View user's profile Send private message Visit poster's website
hitwalker
Sells PC To Pay For Divorce



Joined:
Posts: 5661

PostPosted: Tue Apr 04, 2006 12:19 pm Reply with quote

yeah well known..has a lot of victims...
no sentinel?
 
View user's profile Send private message
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Tue Apr 04, 2006 12:29 pm Reply with quote

NukeSentinel(tm) installed and configured?

Any photo galleries which all have known exploits?

Forums up to date (v2.0.19) with all patches?

Nuke up to date with all patches?
 
View user's profile Send private message
panda
Hangin' Around



Joined: May 09, 2004
Posts: 32

PostPosted: Tue Apr 04, 2006 12:38 pm Reply with quote

Hi mine got done as well, I am upto date on my Forums & Sentinel Gallery i am using is coppermine the newest one. Is there anyway to sort this out ?

Thanks

Panda
 
View user's profile Send private message
Raven







PostPosted: Tue Apr 04, 2006 12:54 pm Reply with quote

Review your access logs to see how they got in. I would suspect Coppermine right off the bat.
 
panda







PostPosted: Tue Apr 04, 2006 1:12 pm Reply with quote

Access logs are huge !! what should i be looking for ? !! nothing is standing out !!
 
panda







PostPosted: Tue Apr 04, 2006 1:51 pm Reply with quote

Does this look line anything dodgy ?!!

EDIT !!


Last edited by panda on Tue Apr 04, 2006 3:08 pm; edited 1 time in total 
kenwood
Worker
Worker



Joined: May 18, 2005
Posts: 119
Location: SVCDPlaza

PostPosted: Tue Apr 04, 2006 2:21 pm Reply with quote

Thats a nice script but je better strip the link out .
And yes there is your bug in your site
 
View user's profile Send private message Visit poster's website
panda







PostPosted: Tue Apr 04, 2006 3:08 pm Reply with quote

I know there is a bug in my site !!
 
mrix







PostPosted: Tue Apr 04, 2006 3:24 pm Reply with quote

Both my sites have the latest sentinal and updates patches and the latest forum patches I did find that I was using the vwar clan install on one of my sites and that has just had issues I have updated that and hope that fixed it???? Raven is it possible you could look at my logs as I am lost with them Confused
Thanks
mrix
Michael Rixon [ Only registered users can see links on this board! Get registered or login! ]
the site that has vwar running is this one [ Only registered users can see links on this board! Get registered or login! ]
 
kenwood







PostPosted: Tue Apr 04, 2006 3:29 pm Reply with quote

panda wrote:
I know there is a bug in my site !!

Vwar is the bug panda its not secure .
 
mrix







PostPosted: Tue Apr 04, 2006 3:36 pm Reply with quote

I have gone to the vwar site and have updated it with the new functions_install.php they suggest would you say this is secure?
thanks
mrix
 
panda







PostPosted: Tue Apr 04, 2006 3:40 pm Reply with quote

Mrix, how did you sort your site out ?

Thanks

Andy
 
Raven







PostPosted: Tue Apr 04, 2006 3:45 pm Reply with quote

Check [ Only registered users can see links on this board! Get registered or login! ] for 2 days of huge announced exploits with vwar. If you use sQuery, search your logs for sQuery. That's how many sites are being cracked right now. The kiddies are doing searches on Google for things like squery+4.5 to locate vulnerable sites.
 
kenwood







PostPosted: Tue Apr 04, 2006 3:47 pm Reply with quote

This site [ Only registered users can see links on this board! Get registered or login! ] is not secure mrix
 
panda







PostPosted: Tue Apr 04, 2006 3:57 pm Reply with quote

I have loads of lines like this one

edit

from ip address 84.51.41.166 are these lot from Turkey ?

Also how do i correct it ?

Many Thanks

Andy


Last edited by panda on Tue Apr 04, 2006 4:00 pm; edited 1 time in total 
kenwood







PostPosted: Tue Apr 04, 2006 4:00 pm Reply with quote

a solution i dont now panda but please edit the link and read [ Only registered users can see links on this board! Get registered or login! ]
 
Raven







PostPosted: Tue Apr 04, 2006 4:14 pm Reply with quote

Ban Turkey completely from your site. See
[ Only registered users can see links on this board! Get registered or login! ] [ Only registered users can see links on this board! Get registered or login! ]
 
VinDSL
Life Cycles Becoming CPU Cycles



Joined: Jul 11, 2004
Posts: 614
Location: Arizona (USA) Admin: NukeCops.com Admin: Disipal Designs Admin: Lenon.com

PostPosted: Tue Apr 04, 2006 4:25 pm Reply with quote

panda wrote:
Access logs are huge !! what should i be looking for ? !! nothing is standing out !!

Probably a sql injection... Do a search for 'nuke_config' too. Wink

_________________
.:: "The further in you go, the bigger it gets!" ::.
.:: VinDSL's Lenon.com | The Disipal Site ::.

Last edited by VinDSL on Tue Apr 04, 2006 4:28 pm; edited 1 time in total 
View user's profile Send private message Visit poster's website ICQ Number
panda







PostPosted: Tue Apr 04, 2006 4:26 pm Reply with quote

Cheers i'll being doing that one. Just need to try and correct my Site now !!
 
hitwalker







PostPosted: Tue Apr 04, 2006 4:28 pm Reply with quote

as i was trying to help panda and the used code couldnt be used in public i send you a pm,would help if you read it and replied.
 
mrix







PostPosted: Tue Apr 04, 2006 4:35 pm Reply with quote

Quote:
Mrix, how did you sort your site out ?

Thanks

Andy


I just uploaded a backup through cpanel and updated the vware

thanks
mrix
 
evaders99
Former Moderator in Good Standing



Joined: Apr 30, 2004
Posts: 3221

PostPosted: Tue Apr 04, 2006 4:37 pm Reply with quote

Good to report whoever's hosting the hacker's website too [ Only registered users can see links on this board! Get registered or login! ]

_________________
- Star Wars Rebellion Network -

Need help? Nuke Patched Core, Coding Services, Webmaster Services 
View user's profile Send private message Visit poster's website
panda







PostPosted: Tue Apr 04, 2006 4:38 pm Reply with quote

Bugger last backup i did was Jan 06 Crap !! I presume ya mean DB Backup !!

Walker you have PM

Cheers

Andy
 
mrix







PostPosted: Tue Apr 04, 2006 4:42 pm Reply with quote

I have just noticed at the bottom of my htaccess file these added????

deny from 86.16.61.105
deny from 202.149.36.158
deny from 80.74.199.146
deny from 87.82.20.199

anyone have any idea who they are???

cheers
mrix
 
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 7.6

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©