| Author |
Message |
diablo Hangin' Around

Joined: Feb 01, 2004 Posts: 34
|
Posted:
Wed Apr 07, 2004 1:38 am |
|
Well ive been reading this forums about all the hack attacks and vulnerabilities but i dont know where to start. I have a pphpnuke gaming site running 6.9 autoinstall with phpbb2.0.6 forums in it. Last night someone posted in my public area my administrator account md5 password. i checked the mysql tables and it was the right one. Obviously i changed the password but i have some sort of vulnerability on the site. Where's the best place to start to block the leaks? Is there a script to run to check the secuirty?
Thanks |
|
|
|
 |
Nukeum66 Life Cycles Becoming CPU Cycles

Joined: Jul 30, 2003 Posts: 551 Location: Neurotic, State, USA
|
Posted:
Wed Apr 07, 2004 3:45 am |
|
Apply PHP-Nuke Patched Series By Chatserv for your version, you can find a link on the index page. Then you may want to install Raven's Hack Alert script located here>> , then possibly a ban system. |
|
|
|
 |
diablo Hangin' Around

Joined: Feb 01, 2004 Posts: 34
|
Posted:
Wed Apr 07, 2004 4:36 am |
|
Incidently some more info. I use ip logger and i logged this ip 66.185.84.200 and he used the name of Xboit |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Wed Apr 07, 2004 5:08 am |
|
Look the IP up at arin. Then contact the abuse address and provide them his IP, date, time, timezone, your IP, name, and the exploit he used from your logs. He used the UNION exploit. Get my hackattempt script. |
|
|
|
 |
diablo Hangin' Around

Joined: Feb 01, 2004 Posts: 34
|
Posted:
Wed Apr 07, 2004 5:37 am |
|
Thanks for the info. I have installed your hack attempt scrip now and am looking at the chatserv script although it looks a bit daunting. |
|
|
|
 |
diablo Hangin' Around

Joined: Feb 01, 2004 Posts: 34
|
Posted:
Mon Apr 12, 2004 1:55 am |
|
Thanks for script, captured one last night.
NetRange: 24.215.128.0 - 24.215.255.255
CIDR: 24.215.128.0/17
NetName: ERLK-CBL-TW-NYC
NetHandle: NET-24-215-128-0-1
Parent: NET-24-0-0-0-0
NetType: Direct Allocation
NameServer: ITCHY.MINDSPRING.NET
NameServer: SCRATCHY.MINDSPRING.NET
Comment:
RegDate: 2003-06-26
Updated: 2003-10-17
OrgAbuseHandle: ABUSE60-ARIN
OrgAbuseName: ABUSE TEAM
OrgAbusePhone: +1-404-815-0770
OrgAbuseEmail:
REMOTE_ADDR : 24.215.132.163
20SELECT%20user_id,username,user_password%20FROM%20nuke_users/*
REQUEST_URI : /phpnuke/hackattempt.php?name=Downloads&d_op=viewdownload&cid=-1%20UNION%20SELECT%20user_id,username,user_password%20FROM%20nuke_users/*
SCRIPT_NAME : /phpnuke/hackattempt.php
Is that what i need to send the abuse email?
Thanks again
 |
|
|
|
 |
|
|
|
|