PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Dacubz
Worker
Worker


Joined: Apr 27, 2004
Posts: 156
Location: Homer Glen, Illinois

PostPosted: Tue Dec 27, 2005 6:39 pm Reply with quote Back to top

Something has corrupted my site, and is trying to force an image download a file expl1_tank.wmf from trust4free.ws every time my index.php is accessed. I overwrote my index.php and it appears OK for now. How can it have happened, and how can I stop it from happening again? I'm running Raven's 7.6 distro with Sentinel BTW.
View user's profile Send private message Visit poster's website
hitwalker
Sells PC To Pay For Divorce


Joined:
Posts: 5661

PostPosted: Tue Dec 27, 2005 7:14 pm Reply with quote Back to top

Well i doubt that..
Every idiot can try to abuse a site or try to hack it.
But it would help if you could provide more info...
View user's profile Send private message
Dacubz
Worker
Worker


Joined: Apr 27, 2004
Posts: 156
Location: Homer Glen, Illinois

PostPosted: Tue Dec 27, 2005 8:21 pm Reply with quote Back to top

Doubt what, and What kind of info should I provide?
View user's profile Send private message Visit poster's website
hitwalker
Sells PC To Pay For Divorce


Joined:
Posts: 5661

PostPosted: Tue Dec 27, 2005 8:34 pm Reply with quote Back to top

well how do you know this?
How do you know they are using your index.php ?
View user's profile Send private message
montego
Site Admin


Joined: Aug 29, 2004
Posts: 9136
Location: Arizona

PostPosted: Tue Dec 27, 2005 9:26 pm Reply with quote Back to top

Dacubz, the base RavenNuke76 distribution should not have allowed this to happen. Now, if you have installed other modules or hacks which allow file uploads, such as Copermine, or a forum file upload mod, or some form of chat module, that could have been the way they broke in... Again, that is if you are certain your index.php was overwritten. Also, are you sure that you configured NukeSentinel per the provided instructions?
View user's profile Send private message Visit poster's website
Dacubz
Worker
Worker


Joined: Apr 27, 2004
Posts: 156
Location: Homer Glen, Illinois

PostPosted: Wed Dec 28, 2005 8:03 pm Reply with quote Back to top

I don't have anything unusual installed, but one of my users did some research and came up with this. I haven't done anything besides overwrite my index.php so far.
Only registered users can see links on this board!
Get registered or login to the forums!



Domain Name: TRUST4FREE.WS
Registrant: personal

Administrative Contact:
Only registered users can see links on this board!
Get registered or login to the forums!

18666254678

Registrar:
Rustelekom (www.NameServers.ru)
1 866 6254678
Only registered users can see links on this board!
Get registered or login to the forums!


Domain created on 2005-10-15 10:10:39
Domain last updated on 2005-10-15 10:10:39

Name servers:

ns0.xname.org
ns1.xname.org
View user's profile Send private message Visit poster's website
Dacubz
Worker
Worker


Joined: Apr 27, 2004
Posts: 156
Location: Homer Glen, Illinois

PostPosted: Wed Dec 28, 2005 8:29 pm Reply with quote Back to top

Reported to the host also, but I was wondering if this could have been caught.
View user's profile Send private message Visit poster's website
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Thu Dec 29, 2005 3:27 am Reply with quote Back to top

Well you'd need to look at your access logs to see how he got it. There's gotta be a vulnerable part somewhere.. usually its an uploading script
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum