Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 07:00:15 PM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite.
155550 Posts in 21714 Topics by 7737 Members
Latest Member: gx-world
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: Website Hack  (Read 338 times)
ddombadoh

Offline Offline

Posts: 24


« on: July 11, 2011, 09:39:17 AM »

Hello All,

I have recently been attacked by hackers on my website. I can't seem to know the point of entry. The main index.php file was completely replaced by another, containing malicious code. My admin password was also replaced and my email was changed, all in the database. The most frequently attacked is the media folder, where some strange files have been placed. I also have the index.php page in admin directly replaced. Please help, as this is becoming a nightmare for me. I have to keep on checking on the site and replacing files that have been hacked. Any help will be greatly appreciated.

Thank you.
Logged
DarkViper
Development Team
*****
Offline Offline

Posts: 1253


« Reply #1 on: July 11, 2011, 09:52:55 AM »

First the much important steps:

  • change the password of your webspace admintool and your FTP account also
  • change the password of your WB-admin account
  • check the rights of all other WB-users and restrict their rights to a absolute minimum
  • clean up your installation / webspace
  • if your site still becomes defaced anyway, contact your hosting provider

these are the first steps only, if it does not help, response please.

Important: use secure passwords only! At least 8 chars (mixed upper- lowercase, numbers, special chars). Never use words which can be found in any dictionary or some names, birthday, and so on..)
Logged

Anleitungen lesen und selber nachdenken ist anstrengend...  Da lass ich doch lieber andere für mich denken...

In 1984:  Nineteen Eighty-Four is a unrealistic utopia!!
In 2012:  Nineteen Eighty-Four is a little piece only of our reality!!
Bramus
Forum Team
*****
Offline Offline

Posts: 601


WWW
« Reply #2 on: July 14, 2011, 08:59:54 AM »

as we dont know what version you are running of the CMS, but keep in mind there was a vulnerability in the SQL Backup module (you can find it through the admin settings). You might want to remove that module as well.

Further on also change you MySQL password, FTP and all other passwords you were using in the environment as mentioned above.
Logged

BRAMUS Internet Services
ddombadoh

Offline Offline

Posts: 24


« Reply #3 on: July 14, 2011, 12:11:38 PM »

Thank you all. I have implemented all the above measures and now observing to see any improvements. Thank you all once again. I will definitely return if there is a hack again.

Thank you.
Logged
BlackBird
AddOn Development
*
Offline Offline

Posts: 2069



WWW
« Reply #4 on: July 14, 2011, 12:35:50 PM »

You may install dbWatch... uhm wait, what's the name... dbWatchSite. http://phpmanufaktur.de/cms/downloads.php
Logged

Alle großen Veränderungen beginnen im Kleinen
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!