Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 6.8
Author Message
morpheus_75
Involved
Involved



Joined: Oct 07, 2003
Posts: 302

PostPosted: Mon Apr 26, 2004 10:54 am Reply with quote

Pls guys I need your help. Someone hacked my site and made himself God Admin!!! Obviously I am God Admin too, but I don't know how to delte him and how to prevent him from doing it again!!! What can I do?? Sad
 
View user's profile Send private message
morpheus_75







PostPosted: Mon Apr 26, 2004 11:04 am Reply with quote

OK, I deleted him using mysql... but how to stop him from hacking my site again? Shocked ??
 
bones
Hangin' Around



Joined: Sep 18, 2003
Posts: 36

PostPosted: Mon Apr 26, 2004 11:11 am Reply with quote

go to http://www.ravenphpscripts.com/downloads-cat12.html and download ravens SQL Injection Hack Alert script. that should stop him.
 
View user's profile Send private message Visit poster's website
morpheus_75







PostPosted: Mon Apr 26, 2004 11:20 am Reply with quote

bones wrote:
go to http://www.ravenphpscripts.com/downloads-cat12.html and download ravens SQL Injection Hack Alert script. that should stop him.


I already have that script on. But I didn't receive any alert email and in any case I can't understand HOW he succeeded in becoming GOD ADMIN!!!
 
chatserv
Member Emeritus



Joined: May 02, 2003
Posts: 1389
Location: Puerto Rico

PostPosted: Mon Apr 26, 2004 11:35 am Reply with quote

http://www.ravenphpscripts.com/postx1252-0-0.html
 
View user's profile Send private message Visit poster's website
morpheus_75







PostPosted: Mon Apr 26, 2004 12:03 pm Reply with quote

Thanks Chat! Smile
I've just applied your fix. I have a question for you. In your opinion, how did the hacker suceed in becoming God Admin? Did he enter mysql DB? Od did he hack some file via web?
 
chatserv







PostPosted: Mon Apr 26, 2004 12:13 pm Reply with quote

Have you opened any pm that had a broken image in it? other than that they could have inserted the code through any vulnerable section of code.
 
morpheus_75







PostPosted: Mon Apr 26, 2004 12:29 pm Reply with quote

chatserv wrote:
Have you opened any pm that had a broken image in it? other than that they could have inserted the code through any vulnerable section of code.


No, but I noticed that many PMs (not only sent by me) do not reach the users Confused and the site is quite slow...
Btw... do u think ur fix will prevent him from succeeding again?
 
morpheus_75







PostPosted: Tue Apr 27, 2004 8:26 am Reply with quote

AGAIN! My site was hacked again! I found another GOD ADMIN (waraxe2) in the admin menu and there was a change in a news in the home page. How is this possible? Anyone can help?? Sad
 
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Tue Apr 27, 2004 8:28 am Reply with quote

Check your log and find out what he used to hack in. Then PM me the URL he used. In the mean time, rename your admin.php file to something else. This will lock you out too but better safe than sorry right now!
 
View user's profile Send private message
chatserv







PostPosted: Tue Apr 27, 2004 8:49 am Reply with quote

Also email me your admin.php file.
 
morpheus_75







PostPosted: Tue Apr 27, 2004 9:07 am Reply with quote

Thanj you both, guys! I'll do what you've told me to

P.S.: Raven, how can I find out what he used to hack in? In other words... would you tell me how to check my log? Embarassed
 
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 6.8

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©