Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

My site was hacked

Asked Modified Viewed 76,630 times
P
Pippi
P
Pippi 10
  • Member, joined since
  • Contributed 65 posts on the community forums.
  • Started 13 threads in the forums
  • Started this discussions
asked
Member

Just want to share so others can learn.

I had still PHP-fusion v 7.02.05, got hacked, got this information from my host:

Malware uploaded through weakness in outdated PHP-fusion script.
Files uploaded by hacker:
administration/Dlogoff.php
administration/wishlistl08.php
viewpage.php
wp-conf.php

Problem is fixed, now I have updated all my sites to 7.02.06.:G
0 replies

142 posts

H
Homdax
H
Homdax 10
  • Fusioneer, joined since
  • Contributed 2,246 posts on the community forums.
  • Started 108 threads in the forums
answered
Fusioneer

I have cleaned up the thread codewise. If you lack something you considered important, well I removed it. We can not risk any AV company detecting and going bananas over this site. PLEASE BE CAREFUL WITH CODE USED IN HACKS OR EXPLOITS.
0 replies
P
PolarFox
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
answered
Veteran Member

Peoples! Use pastebin or something like for these codes, please.
0 replies
M
MeTRoiD
M
  • Member, joined since
  • Contributed 114 posts on the community forums.
  • Started 11 threads in the forums
answered
Member

I got hacked again :D ..
The same files, the same thing..
0 replies
T
Tyler
T
Tyler 10
Helping, would be pointing you in the right direction, not doing it all for you.
  • Member, joined since
  • Contributed 198 posts on the community forums.
  • Started 3 threads in the forums
answered
Member

Well I could only guess why... Insecure add-ons/modifications, wrong server settings or a combo... Sorry to hear that.

Why hasn't this site been breached? - if it's within fusion.... I've been skeptical but this site has almost never had issues... or they've never admitted it
0 replies
P
PolarFox
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
answered
Veteran Member

MeTRoiD did you cleaned your site? DB, files, changes, passwords?
0 replies
M
MeTRoiD
M
  • Member, joined since
  • Contributed 114 posts on the community forums.
  • Started 11 threads in the forums
answered
Member

NO :D .. I guess needed to :D ..
Ah.. Will do that now..
0 replies
A
alecxz
A
alecxz 10
  • Junior Member, joined since
  • Contributed 19 posts on the community forums.
  • Started 4 threads in the forums
answered
Junior Member

my problem ... spam email.. i need help

www.alecxz.altervista.org/infusions/image_hosting/thumbs/dbcc8cc86a2cc8ab7bba2164cb0d6d5e.jpg
0 replies
H
Homdax
H
Homdax 10
  • Fusioneer, joined since
  • Contributed 2,246 posts on the community forums.
  • Started 108 threads in the forums
answered
Fusioneer

@alecxz, that is not related to this issue, please make a new thread.

@Tyler, dont go all conspirational on us here hey, we have been hacked, several times, so have sites of mine. There is no reason whatsoever to not admit to that, since 1) if the site is down, it is down rite? and 2) why would we not improve PHPFusion's code if we ourselves may be hacked if not doing so? I know that this site have been down on and off the last year, but as far as I know and have been told it has always been server related issues. You have my word on that.
Domi has spent a great deal of time recently cleaning up and securing the server and even if there may be some odd task left there, we will most likely not suffer from unplanned server related downtime again.

I do not know if the fact that we are currently on our own hosted Virtual Private Server may give us the ability to have a slightly better security, have not looked in to that a lot, but I think it is safe to assume that may be the case.
Edited by Homdax on 24-02-2013 23:02,
0 replies
D
Drbo
D
Drbo 10
WinXP, Opera 12.14
  • Senior Member, joined since
  • Contributed 258 posts on the community forums.
  • Started 55 threads in the forums
answered
Senior Member

Hacked again. Version 7.02.06, Fusion Scan doesn't work... :|
0 replies
T
Tyler
T
Tyler 10
Helping, would be pointing you in the right direction, not doing it all for you.
  • Member, joined since
  • Contributed 198 posts on the community forums.
  • Started 3 threads in the forums
answered
Member

Richard, I was saying the complete opposite of what you were talking about.

I said if there was a flaw in fusion this site would be the first to be breached. Like I said I didn't think this site has been hacked but for all it could of just not been announced.

All I was trying to say is if fusion had faults it would show on this site not just people whom use fusion. That's why I blamed it on insecure add-ons/mods, server settings or both....

You misunderstood me.


For those of you who've been hacked you need to do as other have told you: Change all your passwords. Furthermore you need to make sure every file is removed. Files can be hidden where you aren't going to look and it can be costly if you don't remove them all.
0 replies
H
Homdax
H
Homdax 10
  • Fusioneer, joined since
  • Contributed 2,246 posts on the community forums.
  • Started 108 threads in the forums
answered
Fusioneer

Quote

Richard, I was saying the complete opposite of what you were talking about.
Oops... paranoid thinking...;)
0 replies
D
Drbo
D
Drbo 10
WinXP, Opera 12.14
  • Senior Member, joined since
  • Contributed 258 posts on the community forums.
  • Started 55 threads in the forums
answered
Senior Member

And again... Today hacked only articles.php...
Fake files deleted, all passwords changed. What else?:|
0 replies
R
Rush_
R
Rush_ 10
  • Junior Member, joined since
  • Contributed 34 posts on the community forums.
  • Started 3 threads in the forums
answered
Junior Member

to delevopers:

i can try to apply some improvments for security


define("COOKIE_USER", COOKIE_PREFIX."user");
define("COOKIE_ADMIN", COOKIE_PREFIX."admin");

change to

define("COOKIE_USER", COOKIE_PREFIX."user");
define("COOKIE_ADMIN", ANY_ANOTHER_RANDOM_NAME);

differrent cookie name for users and admins (setted by user).
if it was done before, this injection wasn't injure any site.
0 replies
A
AT0m
A
AT0m 10
  • Junior Member, joined since
  • Contributed 30 posts on the community forums.
  • Started 7 threads in the forums
answered
Junior Member

1 - Address Site Hacked
2 - zone-h.org mirror
3 - Install Only one CMS
4 - trust hosting

then say my php-fusion site hacked
Edited by AT0m on 25-02-2013 16:00,
0 replies
S
SuNflOw
S
Get v9 Infusion by SuN-Infusions here:
https://sun-infusions.de/ (German)
  • Junior Member, joined since
  • Contributed 12 posts on the community forums.
  • Started 5 threads in the forums
answered
Junior Member

Maybe the developers off PHPFusion missed to contact der NSS sites to puplic this BIG secuity misstake. click

It can not be true that somebody fixed this misstake and there is no Sorry or a try to make Users update there pages...

Now everybody is crying because nobody said there is a Secuity problem this big!

I'm very ****ed because nobody tryed to do somethink...

Quote

I am pleased to announce the availability of PHPFusion v7.02.06.

Update: PHPFusion v7.02.06 Update
Full package: PHPFusion v7.02.06

This version is a minor clean-up, where several vulnerabilities have been fixed. PHPFusion v7.02.06 is expected to represent the end of life for the PHPFusion 7.02. A special thank you to Janek Vind for reporting several vulnerabilities.

Christian Damsgaard Jørgensen, PHPFusion Lead Developer


"several vulnerabilities"

Heeeellooohooooo after that I never Update my Page But when there is a:

[size=20]"WARNING: We make a big misstake (since v7.02.01) that allow others to access in every Account on your Website please Update"[/size]

Then I run faster to my site to Update as to my presents under christmas tree.
Edited by SuNflOw on 25-02-2013 16:58,
0 replies
S
SuNflOw
S
Get v9 Infusion by SuN-Infusions here:
https://sun-infusions.de/ (German)
  • Junior Member, joined since
  • Contributed 12 posts on the community forums.
  • Started 5 threads in the forums
answered
Junior Member

Yeah wuheeey. But how long we had v7.02? We need a bigger Announcement as "several vulnerabilities" as German I had to Google what that mean at first.

See what official NSS Germany said to that:
http://phpfusion-support.de/news.php?readmore=496

Austria the same:
http://php-fusion.at/news.php?readmore=23

Why did nobody talked to them to say there is a big security problem?

Edit: Where's Craigs Post? O.o
Edited by SuNflOw on 25-02-2013 17:56,
0 replies
C
Craig
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
answered
Fusioneer

Hi there Sunflow,

I removed my post as I thought maybe my information was not accurate enough.

I hope you can resolve your issues, please carry on!

I would like to offer you My Sincere apologise for posting possibly inaccurate information.

Kind Regards
Craig
0 replies
J
jikaka
J
jikaka 10
www.rusfusion.ru - russian nss
  • Veteran Member, joined since
  • Contributed 946 posts on the community forums.
  • Started 82 threads in the forums
answered
Veteran Member

Quote

Why did nobody talked to them to say there is a big security problem?

I personally warned all Russian users of the vulnerability and immediately updating
0 replies
W
Wanabo
W
Wanabo 10
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
  • Senior Member, joined since
  • Contributed 598 posts on the community forums.
  • Started 94 threads in the forums
answered
Senior Member

Quote

Richard Ainz wrote:

I have cleaned up the thread codewise. If you lack something you considered important, well I removed it. We can not risk any AV company detecting and going bananas over this site. PLEASE BE CAREFUL WITH CODE USED IN HACKS OR EXPLOITS.


I understand your concern, but I would like to see the code so I can scan for it on my server.
I think only if this site performs malicious actions those AV boys goes bananas. Showing the code to warn people I think not.

To compromise: Isn't it possible to show the code only to members? That way searchengines and AV companies won't see the code.

I'll be happy to make a BBCode for that.
0 replies
J
jikaka
J
jikaka 10
www.rusfusion.ru - russian nss
  • Veteran Member, joined since
  • Contributed 946 posts on the community forums.
  • Started 82 threads in the forums
answered
Veteran Member

Quote

I'll be happy to make a BBCode for that.

this bb-code is already there
0 replies

Labels

None yet

Statistics

  • Views 0 views
  • Posts 142 posts
  • Votes 0 votes
  • Topic users 41 members

41 participants

F
F
Falk 131
Need help?, Having trouble?
• View our Documentation for Guides, Standards and Functions
• Name and Organize your Topics and Content correctly in the corresponding Forums for best support results
• Attaching Log Files and Screenshots when reporting issues will help
• Provide with an URL to live example if one exists
• Please read the How to Report an Error post
• Please read and comply with the Code of Conduct

(¯·._.·(¯°·._.·°º*[ Project Manager ]*º°·._.·°¯)·._.·¯)
  • Super Admin, joined since
  • Contributed 6,201 posts on the community forums.
  • Started 639 threads in the forums
  • Answered 11 questions
J
J
janmol 10
...........................
Jan Mølgård
PHP-Fusion, Denmark
Phone: 004528966794
Mail: janmol@wordit.dk
Mail: janm@janm.dk

Testsite version 9: http://php-fusion.dk/fusion_9_test/
  • Veteran Member, joined since
  • Contributed 752 posts on the community forums.
  • Started 256 threads in the forums
H
H
Homdax 10
  • Fusioneer, joined since
  • Contributed 2,246 posts on the community forums.
  • Started 108 threads in the forums
T
T
  • Newbie, joined since
  • Contributed 1 post on the community forums.
G
G
www.gojuryu.net
Online since 1998 & running PHP-Fusion since 2004
  • Member, joined since
  • Contributed 105 posts on the community forums.
  • Started 16 threads in the forums
C
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
V
V
val 10
  • Junior Member, joined since
  • Contributed 40 posts on the community forums.
  • Started 11 threads in the forums
Q
Q
www.php-fusion.co.uk/../../images/smiley/cool.gif

Mike
---------------------------------------
Quartzkyte, admin @ French N.S.S.
  • Senior Member, joined since
  • Contributed 404 posts on the community forums.
  • Started 40 threads in the forums
W
W
Wanabo 10
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
  • Senior Member, joined since
  • Contributed 598 posts on the community forums.
  • Started 94 threads in the forums
K
K
kd6oji 10
  • Junior Member, joined since
  • Contributed 15 posts on the community forums.
  • Started 4 threads in the forums
M
M
  • Member, joined since
  • Contributed 114 posts on the community forums.
  • Started 11 threads in the forums
D
D
Drbo 10
WinXP, Opera 12.14
  • Senior Member, joined since
  • Contributed 258 posts on the community forums.
  • Started 55 threads in the forums
A
A
  • Senior Member, joined since
  • Contributed 725 posts on the community forums.
  • Started 128 threads in the forums
N
N
NetriX 10
Need help? Having trouble?
» View our Documentation for guides, functions and more - including the Getting Started section!
» Attach Log Files and Screenshots when reporting issues
» My support days are usually Mon-Thurs. Send me a PM if urgent.
  • Senior Member, joined since
  • Contributed 566 posts on the community forums.
  • Started 93 threads in the forums
Q
Q
  • Member, joined since
  • Contributed 54 posts on the community forums.
  • Started 23 threads in the forums
F
F
faga 10
I choose a lazy person to do a hard job. Because a lazy person will find an easy way to do it.” - Bill Gates
  • Member, joined since
  • Contributed 158 posts on the community forums.
  • Started 14 threads in the forums
P
P
  • Veteran Member, joined since
  • Contributed 1,633 posts on the community forums.
  • Started 29 threads in the forums
A
A
  • Newbie, joined since
  • Contributed 6 posts on the community forums.
  • Started 2 threads in the forums
H
H
  • Senior Member, joined since
  • Contributed 262 posts on the community forums.
  • Started 28 threads in the forums
B
B
Sorry for my English, but Google is not perfect
  • Newbie, joined since
  • Contributed 9 posts on the community forums.
  • Started 3 threads in the forums
J
J
jikaka 10
www.rusfusion.ru - russian nss
  • Veteran Member, joined since
  • Contributed 946 posts on the community forums.
  • Started 82 threads in the forums
P
P
Pippi 10
  • Member, joined since
  • Contributed 65 posts on the community forums.
  • Started 13 threads in the forums
  • Started this discussions
R
R
Rush_ 10
  • Junior Member, joined since
  • Contributed 34 posts on the community forums.
  • Started 3 threads in the forums
J
J
JoiNNN 10
  • Veteran Member, joined since
  • Contributed 850 posts on the community forums.
  • Started 100 threads in the forums
S
S
Get v9 Infusion by SuN-Infusions here:
https://sun-infusions.de/ (German)
  • Junior Member, joined since
  • Contributed 12 posts on the community forums.
  • Started 5 threads in the forums
T
T
Tyler 10
Helping, would be pointing you in the right direction, not doing it all for you.
  • Member, joined since
  • Contributed 198 posts on the community forums.
  • Started 3 threads in the forums
A
A
Archer 9
  • Member, joined since
  • Contributed 115 posts on the community forums.
  • Started 7 threads in the forums
Z
Z
zizub 10
  • Member, joined since
  • Contributed 156 posts on the community forums.
  • Started 29 threads in the forums
A
A
alecxz 10
  • Junior Member, joined since
  • Contributed 19 posts on the community forums.
  • Started 4 threads in the forums
J
J
  • Newbie, joined since
  • Contributed 4 posts on the community forums.
  • Started 1 thread in the forums
B
B
  • Newbie, joined since
  • Contributed 9 posts on the community forums.
A
A
AT0m 10
  • Junior Member, joined since
  • Contributed 30 posts on the community forums.
  • Started 7 threads in the forums
S
S
Spikey 10
  • Newbie, joined since
  • Contributed 6 posts on the community forums.
I
I
  • Newbie, joined since
  • Contributed 4 posts on the community forums.
  • Started 1 thread in the forums
S
S
  • Junior Member, joined since
  • Contributed 10 posts on the community forums.
S
S
Scurit 10
Website Security & Malware Removal Specialist
http://www.scurit.com
  • Newbie, joined since
  • Contributed 2 posts on the community forums.
A
A
  • Newbie, joined since
  • Contributed 3 posts on the community forums.
S
S
sals_s 10
  • Newbie, joined since
  • Contributed 1 post on the community forums.
A
A
  • Newbie, joined since
  • Contributed 3 posts on the community forums.
  • Started 2 threads in the forums
P
P
  • Junior Member, joined since
  • Contributed 11 posts on the community forums.
  • Started 4 threads in the forums
M
M
  • Newbie, joined since
  • Contributed 1 post on the community forums.

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet