PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
shotokan
Worker
Worker


Joined: Aug 27, 2006
Posts: 153

PostPosted: Sat May 12, 2007 7:40 pm Reply with quote Back to top

I just had my site hacked by someone that added a HTML ref into the forums configuration field where my site description goes.

He removed the description content and added the html ref there forwarind to his hack website.

I use nuke 7.8 patched 3.3

How did he can actually alter a content inside the database? What is the best way to prevent this? Installing Sentinel?
View user's profile Send private message
floppydrivez
Worker
Worker


Joined: Feb 26, 2006
Posts: 210
Location: Jackson, Mississippi

PostPosted: Sat May 12, 2007 8:22 pm Reply with quote Back to top

Sorry to hear that shotokan. Yes sentinel should be your last line of defense and the first step in restoring your site to a secure operating standpoint. No site should be without sentinel in my opinion.
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
fkelly
Moderator


Joined: Aug 30, 2005
Posts: 2064
Location: near Albany NY

PostPosted: Sat May 12, 2007 8:27 pm Reply with quote Back to top

1st I'd look at basic host security issues, like could anyone have compromised your host account, passwords, ftp accounts and the like. That varies by host and by your security procedures, whether you use the same passwords in a bunch of places etc.

Second, Nuke 7.8 has a lot of known security vulnerabilities. Sentinel protects against a lot of them but it can't fix up all the holes. This is especially true if you have 3rd party modules that have vulnerabilities built in.

You need to look at your logs and change passwords and make sure the hackers don't retain access to your tables. Otherwise anything else you would do could very well be spitting into the wind.

Then you might look at RN 2.10.01 which comes with Sentinel built in. But if the hacker has access to your host or your author's table or anything else on your system you really need to determine and eliminate this first.
View user's profile Send private message Visit poster's website
floppydrivez
Worker
Worker


Joined: Feb 26, 2006
Posts: 210
Location: Jackson, Mississippi

PostPosted: Sat May 12, 2007 8:31 pm Reply with quote Back to top

fkelly, that seems a little rehearsed, maybe as if you have said that before.

On a serious note, (I honestly haven't looked to see if it exist already), but that would make a decent sticky for others.
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum