PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 6:51 pm Reply with quote Back to top

I've had my site hacked, parts of the forum deleted and then several modules deactivated.

Quote:
Created By: NukeSentinel(tm) 2.6.01
Date & Time: 2009-02-17 10:36:02 UTC GMT +0000
Blocked IP: 203.130.236.211
User ID: Anonymous (1)
Reason: Abuse-Filter
--------------------
Referer: none
User Agent: libwww-perl/5.805
HTTP Host:
Only registered users can see links on this board!
Get registered or login to the forums!

Script Name: /main/modules.php
Query String: name=News&file=removed
Post String: Not Available
Forwarded For: none
Client IP: none
Remote Address: 203.130.236.211
Remote Port: 36367
Request Method: GET


Now I've put everything right but now can't turn on Admin Auth in Sentinel.
The .htaccess file is chmod 777 (is that right?) but all there is in the box to turn AA on is: Off and Admin CGIAuth. No option to turn it on, and the path in the box below that is correct to the .htaccess file.

Can someone advise please? thanks
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Tue Feb 17, 2009 8:40 pm Reply with quote Back to top

This was a hack against RavenNuke 2.30.00? Was this within an old addon or something different? Please send me the details

I don't know what's missing from Admin Auth, but yes.. it should be chmod 777
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Tue Feb 17, 2009 9:00 pm Reply with quote Back to top

Everyone needs to do this!

Please immediately download and replace the following file:

Download ->
Only registered users can see links on this board!
Get registered or login to the forums!

Unzip captcha.zip
Replace ->/images/captcha.php


Last edited by Raven on Tue Feb 17, 2009 9:27 pm; edited 1 time in total
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Tue Feb 17, 2009 9:11 pm Reply with quote Back to top

Raven, your link is processing it as a .php file Smile
May need to zip it up or rename
View user's profile Send private message Visit poster's website
Palbin
Site Admin


Joined: Mar 30, 2006
Posts: 2408
Location: Pennsylvania

PostPosted: Tue Feb 17, 2009 9:18 pm Reply with quote Back to top

"save as" for now
View user's profile Send private message Visit poster's website
spasticdonkey
RavenNuke(tm) Development Team


Joined: Dec 02, 2006
Posts: 1254
Location: Texas, USA

PostPosted: Tue Feb 17, 2009 9:20 pm Reply with quote Back to top

just displays an error message in the downloaded php file
View user's profile Send private message
Palbin
Site Admin


Joined: Mar 30, 2006
Posts: 2408
Location: Pennsylvania

PostPosted: Tue Feb 17, 2009 9:22 pm Reply with quote Back to top

You are correct Sad I see what Evadors99 is talking about now.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Tue Feb 17, 2009 9:28 pm Reply with quote Back to top

I have corrected the file name/link.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Tue Feb 17, 2009 10:14 pm Reply with quote Back to top

Thanks for the fix, all my production domains contain the new file now.

Cheers
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Tue Feb 17, 2009 10:27 pm Reply with quote Back to top

Perhaps you need to uncomment the section in .htaccess under:

# Start of NukeSentinel(tm) admin.php Auth


Last edited by dad7732 on Tue Feb 17, 2009 10:28 pm; edited 1 time in total
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 10:28 pm Reply with quote Back to top

Thanks for that.

evaders99 I just have the straight RavenNuke 2.30.00 with no addons, extras or mods.

Still not able to put Admin Auth to ON, there's nothing there to do so.

I'll pm you my site details so you can check it if you like. Can't understand it.
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Tue Feb 17, 2009 10:30 pm Reply with quote Back to top

Re: turning adminAuth on / off

You running PHP 4? If so, check out the setting for "register_globals" ... off or on?
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 10:34 pm Reply with quote Back to top

Sorry where would I find that?

Heads spinning a bit at the moment after sorting the site out. Sorry.

PHP 5.2.5
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Tue Feb 17, 2009 10:46 pm Reply with quote Back to top

cornishpixie wrote:
Thanks for that.

evaders99 I just have the straight RavenNuke 2.30.00 with no addons, extras or mods.

Still not able to put Admin Auth to ON, there's nothing there to do so.

I'll pm you my site details so you can check it if you like. Can't understand it.


Do you see HTTP Auth instead of CGI Auth?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 10:59 pm Reply with quote Back to top

All it says in the Admin Auth drop down box is OFF or Admin CGIAuth

Yet the path to the file is correct. There's no ON option in the box. The file .htaccess is chmodded 777 and I've just redownloaded RavenNuke 2.3.00 again and uploaded the .htaccess file again. Still doesnt show in the box.

Earlier I uncommented

# Start of NukeSentinel(tm) admin.php Auth as dad7732 suggested and got an internal server error, so hence downloading new file and reuploading it.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Tue Feb 17, 2009 11:05 pm Reply with quote Back to top

Admin CGIAuth is what you want. It is dependent on .htaccess and .staccess. There is an exact procedure to creating the ids and passwords that go into the .staccess file. Have you followed the instructions in the HowToInstall guide? I don't mean that as an insult!

Also, that line you uncommented is just a comment and the 500 error you received is the result of a syntax error in .htaccess since Apache had no idea what it meant Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 11:09 pm Reply with quote Back to top

I didnt take it as an insult Raven. It's 5am here and been trying to get the site working since 11pm. lol So I'm a bit fuzzy at the moment.

OK I'll switch to CGIAuth. I did read the instructions when I installed the site last year, and it's been fine til it was hacked tonight. But will change to CGIAuth now.

I'll read the install instructions again, as I will need to add something to .staccess file I think?
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Tue Feb 17, 2009 11:14 pm Reply with quote Back to top

Yes, it's all in there. Tell you what. PM to me the following information and I'll set it up.

Site url, adminid, passwd
ftp url, id, passwd
phpmyAdmin url, id, passwd

The reason I need/want all that information is because I want to be sure that the buttwipe didn't leave any other back doors Wink

I am so very, very, very, sorry for the damage that was done through the hole in RN.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 11:30 pm Reply with quote Back to top

Sorry Raven was doing the CGIAuth thingie.

Ok will pm you the info now, thank you so much, I'm really tired at the moment.
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Tue Feb 17, 2009 11:46 pm Reply with quote Back to top

All info pm'd Raven. Thanks for your help.

Off to bed now as it's 5.45AM here. Will check back here around 11AM my time.

Good luck. Hope he's not done much damage.

Raven it's not your fault, its such a complex piece of software, and you all do such a great job that someone somewhere is bound to want to challenge your skills. The price of fame eh? lol

Nite my friend.
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Wed Feb 18, 2009 12:43 am Reply with quote Back to top

If you're sure this hack is due to vulnerable spot (time matches with log, code was executed, etc), then no need to message me. Seems like Raven has it covered.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Feb 18, 2009 1:09 am Reply with quote Back to top

All should be well now. I will PM you back your information.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Wed Feb 18, 2009 6:24 am Reply with quote Back to top

Just as a matter of record ...
Quote:
Earlier I uncommented

# Start of NukeSentinel(tm) admin.php Auth


What I said was to uncommment the lines AFTER that entry. Wink

Cheers
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 6:28 am Reply with quote Back to top

LOL Sorry dad7732.

I was half asleep last night, it was 6am UK time and I'd been trying to sort it out since 11pm, so my brain wasn't engaging properly.

Thank you to Raven, for getting it all up and running again for me, you are a STAR!!!!

Went onto my 50+ website for the silver surfers and the forum on there had been hacked. Thankfully I use the forum on RavenNuke on that site as a support forum, and link to an 'external' phpbb3 forum to the main site, so its on a seperate database, which is good cos they only managed to wipe half the forum on there and couldnt touch the main site.

So will be busy today getting that forum up and running again.

I have no idea why kids do this kind of thing. If they put that much energy into something constructive what a great place the world would be eh?

Thank you again everyone! Much much appreciated, and sorry if I was a bit doh! last night, was lack of sleep lol
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Wed Feb 18, 2009 6:40 am Reply with quote Back to top

Quote:
I have no idea why kids do this kind of thing.


Because they can ... Also, the challenge.

Cheers and good luck!!
RavensScripts
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum