PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
studeggle
Hangin' Around


Joined: Mar 19, 2004
Posts: 36

PostPosted: Tue Mar 30, 2004 8:52 am Reply with quote Back to top

Can anyone out there help me find and fix my problem. Almost every single week my index page is getting rewritten on my site and I have to reload it. I'm afraid I don't know alot about securing things or telling how they did it. I am useing Raven's ver of php nuke 7.0 on a linux server that is updated daily with any security patches for linux and the web server software. And I keep chaning my login information. But it just keeps happening. The defacment page is different each time so I don't know if it is lots of people and I have some giant security flaw I am over looking, or the same one useing different sigs to make it look like different people. I would realy appreciate any help with this issue. I run a website for fun but it is starting to not be fun anymore with haveing to redo it almost every week. Crying or Very sad
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Tue Mar 30, 2004 9:08 am Reply with quote Back to top

Have you patched MeG? Actually you might consider dropping it for Gallery or Coppermine at this point I don't know where a patched version is...
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Tue Mar 30, 2004 9:14 am Reply with quote Back to top

And have you applied the latest Security Fix packs from Chatserv that are advertized on my front page? And the couple of patches that have recently been discussed here? My 7.0 was only current as of the date it was released.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
studeggle
Hangin' Around


Joined: Mar 19, 2004
Posts: 36

PostPosted: Tue Mar 30, 2004 9:16 am Reply with quote Back to top

Are you refereing to My eGallery? If so no I did not know there was a problem with it, I will keep tring to get coppermine to work, and deactivate My eGallery (will deactivating it be sufficent, or do I need to remove all of its files?)
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
studeggle
Hangin' Around


Joined: Mar 19, 2004
Posts: 36

PostPosted: Tue Mar 30, 2004 9:17 am Reply with quote Back to top

thankyou, Yes I have applied the security fixes discussed on you front page Raven.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Tue Mar 30, 2004 9:48 am Reply with quote Back to top

Then its probably MyeGallery you might find info at nukecops on a fix or updated version.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Tue Mar 30, 2004 11:27 am Reply with quote Back to top

Reference this article
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
studeggle
Hangin' Around


Joined: Mar 19, 2004
Posts: 36

PostPosted: Tue Mar 30, 2004 6:58 pm Reply with quote Back to top

Thank you very much Very Happy thanks to you two I found the problem and the culprit Very Happy now I can block his/her IP and fix my problem. Incase you want to know here is a copy from my log.

Host: 62.251.187.10 Url: /index.html Http Code : 200
Date: Mar 30 14:19:54 Http Version: HTTP/1.1" Size in Bytes: 270020
Referer:
Only registered users can see links on this board!
Get registered or login to the forums!
Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 9Cool
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
studeggle
Hangin' Around


Joined: Mar 19, 2004
Posts: 36

PostPosted: Tue Mar 30, 2004 7:07 pm Reply with quote Back to top

I also just found this guy that used the exploit after my site was defaced but before I was able to fix it. He didn't change anything, but the code (
Only registered users can see links on this board!
Get registered or login to the forums!
) to looks like he was able to pull everything about my server off. Should I change login information for all domains running on this server?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum