Welcome, Guest. Please login or register.
Did you miss your activation email?
May 27, 2012, 04:54:18 AM

Login with username, password and session length
Search:     Advanced search
Interested in joining the WebsiteBaker team?
For more Information read here or on our new website.
155555 Posts in 21715 Topics by 7737 Members
Latest Member: gx-world
* Home Help Search Login Register
Pages: [1]   Go Down
Print
Author Topic: Site hacked: index.php  (Read 710 times)
dellington

Offline Offline

Posts: 86


« on: February 15, 2008, 09:56:02 PM »

We found this week that our website had been hacked with a line of code added to the end of the index.php file at the root level of the WB installation (which is also the root level of our domain). The code attempted to run (install?) an applet on the user's computer. I found a very small amount of information on google pertaining to this code, indicating the website that it linked to "exploits browser security".

I have removed the code and all seems well but I don't know what I should do to prevent future problems. It doesn't seem like a WB hack, but more likely at the server level.

Any ideas?
Logged
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7973



WWW
« Reply #1 on: February 16, 2008, 07:48:27 AM »

Hello,

1.) You should ask your hoster for the server logs. This way you got the information when and how the changes are made.

2.) As index.php and config.php don't need to be changed after WB is installed a good ideas is to set chmod to 0444. This cannot prevent hacks through the shell of the server but it could prevent hacks from scripts.

3.) Please use the latest WB version (2.6.7) in kombination with FCKEditor major 2.7.5 (WB modul version number). All other Editor have a secutiy hole wich allows to add bad/executable code to your WB files.

Matthias
Logged
CMD

Offline Offline

Posts: 7


« Reply #2 on: February 16, 2008, 10:33:11 AM »

Hello,

does
All other Editor....

include the shipped HTMLArea also?

regards,
Christian
Logged

my ~ is my castle
I love my "Spamassi"  tongue http://www.amran.de/pages/admin-fun/spam-top10.php
Concerned 'bout the net?  undecided http://www.amran.de/pages/admin-fun/not-funny.php (! might have some loading ti
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7973



WWW
« Reply #3 on: February 16, 2008, 11:35:00 AM »

Hello,

Quote
include the shipped HTMLArea also?

I think so.

Matthias
Logged
CMD

Offline Offline

Posts: 7


« Reply #4 on: February 16, 2008, 11:46:55 AM »

Hi,

I think so.

ok, so i'll try FCKEditor then.
Thanks!

Christian
Logged

my ~ is my castle
I love my "Spamassi"  tongue http://www.amran.de/pages/admin-fun/spam-top10.php
Concerned 'bout the net?  undecided http://www.amran.de/pages/admin-fun/not-funny.php (! might have some loading ti
Pages: [1]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!