Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2012, 02:40:08 AM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155476 Posts in 21708 Topics by 7734 Members
Latest Member: rofroodoOvego
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: HELP I've been hacked!  (Read 846 times)
pszilard

Offline Offline

Posts: 73


WWW
« on: January 06, 2009, 02:44:37 PM »

Pls help! I know this isn't a WB problem, but my WB site had been hacked, and where else can I go for expert help than here?

My site shows a blank page, i.e. it doesn't display any code/content. If I connect via FTP, I can see all files seemingly unchanged! If I access via Plesk site control, I see that a number of files and folders had changed ownership to Apache, whereas before they were my domain id. This includes most (but not all) of the WB template folders.

If I log in to WB, and change the site template to one which has my id as owner, then the site shows up again. If I change it back to the template I want to use (now owned by Apache) than the site disappears!

I cannot uninstall the templates or reinstall them.

I would be grateful for any assistance. You can also PM me or email me at remektek-at-gmail-dot-com

Thanks in advance,
Logged

Paul Szilard
WB user since Dec 2007:
http://www.remektek.com.au/wb
http://photos.remektek.com.au/ for my photo portfolio
Ruud
WebsiteBaker Org e.V.

Offline Offline

Posts: 2295



WWW
« Reply #1 on: January 06, 2009, 02:50:05 PM »

I assume you cannot set the files to your domain id again, so you will need the help of your hoster.

Just ask them to reset all your files to your id.
Also notify them about what happened, it might very well be their main site (Apache user) that was hacked.

Ruud
Logged

Professional WebsiteBaker Solutions
doc
Guest
« Reply #2 on: January 06, 2009, 03:03:14 PM »

Hello,

have you tried to delete the specific template folder via FTP (remember to back up files first)? If this works, use the Admin Tool Reload Addons and then install the template again via the WB backend? If this does not work, you need to contact your hoster to set the right permissions.

Regards Christian
Logged
pszilard

Offline Offline

Posts: 73


WWW
« Reply #3 on: January 06, 2009, 09:55:41 PM »

I have opened an Emergency Help Desk Ticket with the hosting people, but it is still before their opening time.

I cannot delete or change or even access the contents of the folders Sad and cannot remove or reinstall templates.

Could someone point me to instructions on how to secure a WB site? I do not understand .htaccess well, and would like a summary of the correct "hardened" file permissions. Is this described somewhere for WB?

Thanks.
Logged

Paul Szilard
WB user since Dec 2007:
http://www.remektek.com.au/wb
http://photos.remektek.com.au/ for my photo portfolio
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7972



WWW
« Reply #4 on: January 06, 2009, 10:02:56 PM »

Hello,

The question is not how to secure WB, the question must be how to secure the server. On all known hacked pages it was not a WB security hole it was hacke due to server security misskonfigurations.

The first step must be to get the logs from your hoster. Only there you can see when and how your page was hacked.

If you use WB 2.7 and the latest FCKEditor WB should be secure. If you use an older version of WB or an older VErsion FCKEditor or another Editor maybe this could be the hole where a hacker could intrude a WB page.

Matthias
Logged
pszilard

Offline Offline

Posts: 73


WWW
« Reply #5 on: January 06, 2009, 10:46:50 PM »

Hi Matthias,

Yes, you are absolutely right that it is the server that needs securing. However as I am a novice in this (and many other) area, I would like a checklist on what the correct access settings are for WB files. e.g. should config.php be set to 644, or 444? etc.

Also how to use .htaccess properly - I would expect this to be a non-WB guideline, so I just ask for guidance here as I have great respect for the skills of people like you and others.

Thanks again...
Logged

Paul Szilard
WB user since Dec 2007:
http://www.remektek.com.au/wb
http://photos.remektek.com.au/ for my photo portfolio
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7972



WWW
« Reply #6 on: January 07, 2009, 06:50:08 AM »

Hello,

the answer of your question depends from your server config. Runs Apache as modul or as cgi, wich php settings are made, is the wwwrun-user the same as the ftp user .....

Basically the lowest permissions with wich WB works are the best. So Files and folders wich needs to be written needs write permissions (this could be 644 until 755 or even 777 depending on your server config).

All Files wich needs not to be changed only needs read permissions. A good idea is to set config.php and all index.php (except templartes index.php) to chmod 444.

Also you can double secure the admin folder (the admin backend) by using .htaccess with a password (if htaccess is allowed on your server). And a simple renaming the admin folder in the WB options and with ftp to another name is also a possibility to make hackers the life not easy.

But always remember, if a hacker can hack your server because of a unsecure server konfiguration, all these steps doesn't matter. As soon as a hacker has access to the server itself, he change whatever he want. So again, the best is to secure the server and running WB with default permissions.

Matthias
Logged
pszilard

Offline Offline

Posts: 73


WWW
« Reply #7 on: January 07, 2009, 07:03:57 AM »

Thanks Mathias.

The good news is that it was determined that my problems were the result of upgrading PHP from 4 to 5, and the hoster's sys admin had to reset accesses. So that's a big relief!

I will try to implement your suggestions, however.

Appreciate your help.

Thanks a million (or 1E6)
Logged

Paul Szilard
WB user since Dec 2007:
http://www.remektek.com.au/wb
http://photos.remektek.com.au/ for my photo portfolio
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!