PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Thu May 13, 2004 5:59 pm Reply with quote Back to top

Hi,

I'm so sick of these hack attempts that ... well, I don't know.

Chatserv, Raven ... thank you for all you do ... I've been following it all for awhile since I was hacked about 3 weeks ago with that stupid "God Admin" deal.

I patched my site ... I installed the HackAlert deal ... and all went well ... UNTIL today ... I get two notices from the protector module ... that a url ... I don't know if I should post it here or not ....

Anyway ... a url was posted ... so I went to go check it out .. and it brings up MY name and my encrypted password!!!!!!!!!!!!!!!!!!!!!!!!!!

What the HELL am I supposed to do now?

Sorry.

Okay ... taking a chill pill Wink

Thanks for the help.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Thu May 13, 2004 6:19 pm Reply with quote Back to top

Why don't you pm the url in question to chatserv or me and we'll sort it out asap for everyone.

Is that while running the most recent version note the update date?
View user's profile Send private message
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Thu May 13, 2004 6:29 pm Reply with quote Back to top

Hi,

I pm'd the url to chatserv.

He said that it works to view the pw through phpmyadmin ... but I'm waiting on a response to see what, if anything they can do with it ... or if they're just letting me know they're still around ...

Thanks!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Thu May 13, 2004 6:30 pm Reply with quote Back to top

Oh,

Forgot to say ... yep, I've got the most recent update and patched version of 7.2.

Haven't done the 7.3 upgrade yet.

Thanks again.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Thu May 13, 2004 6:32 pm Reply with quote Back to top

lmao I was just thinking you won't be able to pm the url if the hackalert onsite here is catching it!
View user's profile Send private message
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Thu May 13, 2004 6:39 pm Reply with quote Back to top

LOL,

So far, so good Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Thu May 13, 2004 7:56 pm Reply with quote Back to top

For anyone wondering we tested this against the last update to the UNION hack prevention and it catches this one too.

Note the code in the default PHPNuke7.3 mainfile.php does not catch the latest UNION exploits on its own.

So be sure you are using the latest version:
Code:

$queryString = strtolower($_SERVER['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString");
die();
}

View user's profile Send private message
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Thu May 13, 2004 8:11 pm Reply with quote Back to top

Just wanted to say "Thanks" real quick.

I really appreciate the help ... and how fast you all reply!

Take care.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Thu May 13, 2004 9:25 pm Reply with quote Back to top

7.3 is missing a patch in the Downloads module which is covered in PHP-Nuke Patched 2.4, what comes as a surprise is that it does not stop it by default, to my understanding 7.3 includes UT
View user's profile Send private message Visit poster's website
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Thu May 13, 2004 9:30 pm Reply with quote Back to top

Yeah I just peeked its the buggier UT3 code though which was only good for about an hour before an update was released.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Fri May 14, 2004 10:59 pm Reply with quote Back to top

sixonetonoffun wrote:
For anyone wondering we tested this against the last update to the UNION hack prevention and it catches this one too.

Note the code in the default PHPNuke7.3 mainfile.php does not catch the latest UNION exploits on its own.

So be sure you are using the latest version:
Code:

$queryString = strtolower($_SERVER['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString");
die();
}

Doo-dah, Doo-dah Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
newbie
Regular
Regular


Joined: May 03, 2004
Posts: 62
Location: USA

PostPosted: Sat May 15, 2004 7:50 am Reply with quote Back to top

Welcome Back Raven!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Sat May 15, 2004 11:10 am Reply with quote Back to top

Not yet - still gone but took a break from the hospital. Not sure when I'm going back. Maybe tomorrow - Maybe next week Crying or Very sad
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum