Hack or no Hack?

Support for IntegraMOD 141

Moderator: Integra Moderator

Hack or no Hack?

PostAuthor: Watcher » Fri May 08, 2009 8:00 am

Recenly i had an error and could not access my ACP, this was not on just 1 site i had it was on all 5 sites i run, after checking i found that all my index.php pages had a line added at the top of the page on line 1

[code]what is supost to be on line 1 is "<?php"what i found was this<iframe src="http]

so is this a hack or a hole for someone to access your site?
[img=left]http://worldofarkania.net/Downloads/Sig_logo/Steal_Watcher.gif[/img]
User avatar
Watcher
Integra Member
Integra Member
 
Posts: 183
Likes: 0 post
Liked in: 0 post
Joined: Sun Nov 05, 2006 8:26 pm
Cash on hand: 0.00

Re: Hack or no Hack?

PostAuthor: obiku » Sun May 10, 2009 10:04 am

It look likes your site has been hacked.

Also the other post:
http://www.integramod.com/forum/viewtop ... =18&t=5430
The message you see, is not one of integraMOD.
I think this IFrame is doing this, phishing attempt
http://www.familie-smit.nl
http://portfolio.familie-smit.nl

Do not tsunami my inbox... instead use the forums...
Hard work may not kill me, but why take a chance?

[hr]
User avatar
obiku
Dev Team
Dev Team
 
Posts: 218
Likes: 0 post
Liked in: 0 post
Joined: Tue May 02, 2006 10:22 am
Cash on hand: 0.00
Location: level 8

Re: Hack or no Hack?

PostAuthor: .QUACK.Major.Pain » Wed May 13, 2009 2:26 pm

It is something a hacker left behind. Seen several of those in the screenshots folder.

As for your pink bar message, it's a security setting.
Not recognized by most people, because by default it is deactivated.

I posted in the other thread how to turn it off.

You might want to consider changing your FTP password, your database password, and your forum password.
Maybe have your admins change forum password also in case someone was comprimized.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: Hack or no Hack?

PostAuthor: MWE_001 » Fri May 15, 2009 12:39 pm

I too agree that this is a hack. Another option is, if you are not using downloads, then chmod the pafiledb/images/screenshots folder to 755 even better would be 644.

If you are using the screenshots for downloads, you will need to insert a .hta file in that folder. They will still be able to upload the files, but the .hta file, if done properly, will stop the scripts from being executed.

I failed to do a search for the proper .hta thread as to what to insert into the file. A quick search here will surely get you pointed in the right direction. If I can find it, I will come back and give you the link to the thread in question.

**EDIT**

Here you go. have a look at this. If it goes to the first page of the thread, simply go to page 2 and look for a reply from helterskelter.

http://integramod.com/forum/viewtopic.p ... e&start=15
"Don't gain the world and lose your soul, wisdom is better than silver and gold" -Bob Marley

If you build it, I can break it! ~ Whispered in the tone of the movie Field of Dreams.
User avatar
MWE_001
Sr Integra Member
Sr Integra Member
 
Posts: 1265
Likes: 0 post
Liked in: 0 post
Images: 12
Joined: Fri Apr 21, 2006 6:59 pm
Cash on hand: 0.00
Location: Illinois


Return to IntegraMOD 141

Who is online

Registered users: Bing [Bot], Google [Bot], Majestic-12 [Bot]