|
|
|
|
![]() ![]() |
Oct 5 2006, 03:28 PM
Post
#1
|
|
|
Premium Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 162 Joined: 10-May 06 Member No.: 23,375 |
I dont know how but my board was hacked by some site by the name Spyhackerz.com .
I use SMF as my board and the main settings file Settings.php was hacked. This file had the password of my DB and i dont know whether they have it or not. They changed its content to the following: CODE <html> <head> <meta http-equiv="Content-Language" content="tr"> <meta http-equiv="Content-Type" content="text/html; charset=windows-1254"> <title>Hacked by Spyhackerz.com</title> </head> <body bgcolor="#000000"> <p align="center"><a href="http://www.spyhackerz.com"> <img border="0" src="http://rootingsabotage.sitemynet.com/sht.jpg" width="503" height="387"></a></p> <p align="center"><font face="Verdana"><b><font color="#FFFFFF"> <a href="http://www.spyhackerz.com"><font color="#FFFF00">www.spyhackerz.com</font></a></font><font color="#FFFF00"> </font></b></font></p> <p align="center"> <EMBED src=http://spyhackerz.com/music/index.mp3 width=20 height=15 autostart="true" loop="true"></p> <p align="center"> </p> </body> </html> Well do you guys know of this.Do those guys have my password now. I changed back my file and my Board is working now. Please help as this is a very very serious matter |
|
|
|
Oct 5 2006, 03:35 PM
Post
#2
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 138 Joined: 16-September 06 From: Montevideo, UY Member No.: 30,036 |
Holy crap! Trap Seventeen security was breached. I think they would have used an FTP server exploit or anything else, which means ALL users security is compromised.
Backup your files in your computer EVERYONE. *Calling BH or OQ* |
|
|
|
Oct 5 2006, 03:44 PM
Post
#3
|
|
|
A computer once beat me at chess, but it was no match for me at kick boxing. ![]() Group: [MODERATOR] Posts: 4,083 Joined: 24-July 05 From: Linix, DOS and Windows…the good, the bad and the ugly Member No.: 9,787 ![]() |
*wait*
You might want to check at the SMF Support Site for clarification about whether this is a problem throughout the SMF Community or solely for your site. Don't start making any assumptions about the Security here at the Trap17 Forums or on other Xisto Sites. There is no reason to believe this is a Trap17 account holder problem until further information is obtained. To begin with, alter your cpanel password immediately. |
|
|
|
Oct 5 2006, 03:58 PM
Post
#4
|
|
|
Premium Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 162 Joined: 10-May 06 Member No.: 23,375 |
Well i have asked the SMF guys lets see.
|
|
|
|
Oct 5 2006, 04:01 PM
Post
#5
|
|
|
Advanced Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 138 Joined: 16-September 06 From: Montevideo, UY Member No.: 30,036 |
Well, yeah, the mod is right (sorry, I can't even pronounce your name, too confusing.
I usually enter nervous stats and it ends on this, saying that I don't trust certain security or etc. Anyways, nobody knows if something is 100% secure. I think that Trap servers are 98% secure. So yeah, change your cpanel pass. I will be trying to report this to the feds unless it was framing, etc. But getting with police is actually no good, so unless this gets on high critical status, I should keep my mouse shut. |
|
|
|
Oct 5 2006, 04:03 PM
Post
#6
|
|
|
To Cool for Cache ![]() Group: [MODERATOR] Posts: 1,123 Joined: 16-June 05 From: Some Place. Member No.: 8,317 ![]() |
Simply, an easy password could be the issue. Sometimes "hackers" are nothing more then "lucky guessers". Make sure your password contains is hard to guess.
Something like "j42dks;;;" would work very nicely infact. (DON'T USE IT). Somelike "coolio" is to easy. Backup all your files, you should do this everytime you change a setting anyways. |
|
|
|
Oct 5 2006, 04:07 PM
Post
#7
|
|
|
Privileged Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: [HOSTED] Posts: 936 Joined: 14-April 05 From: West Chester, PA Member No.: 5,636 |
Most likely what happened is that they put code into one of your db search fields and or logins and depending on the code they used, it can allow them to pull data from your setting files and or from your database giving them access to it. I used to have a phpnuke site and after being hacked, i read a ton of articles on how to secure it. However, it just cant be done since with every new version of software there are new flaws that are created. I would make sure you update your forum to the newest version since the security vulnerabilites will be the least likley known and always update to the new version no matter what anyone tells you. Also, make sure it is hard to identify exactly what type of forum you are using since it will make it harder hack. Finally, change all your passwords just in the case they found them because they will be back if they do.
|
|
|
|
Oct 6 2006, 05:23 AM
Post
#8
|
|
|
Desperately seeking "any key" to continue... ![]() Group: Admin Posts: 3,497 Joined: 23-April 05 From: Trap17 storage box Member No.: 6,042 |
If your account was compromised, there wouldn't be any left of your files and database... right? Think before you assume.
Which version of SMF were you using? And did you follow all SMF standard setting instruction, such as CHMOD? QUOTE A bug in PHP causes a vulnerability in SMF 1.1 RC2-1. You can install this patch (click here to install) to patch your version of 1.1 RC2 to 1.1 RC2-2. We received a report detailing a bug in PHP (improper deletion of hash values in the zend_hash_del_key_or_index() function), causing a vulnerability in SMF. We have addressed this issue in this release. We urge everyone who is using an earlier release of SMF 1.1 to update immediately. So have you upgraded to 1.1 RC3? |
|
|
|
Oct 6 2006, 06:30 AM
Post
#9
|
|
|
Super Member ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 309 Joined: 3-July 06 From: Middle Earth Member No.: 26,018 |
You also may have left the install file in, CHMODDed a file where it wasnt neccesary. All of those things can compromise security.
|