Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

Hacked?

Asked Modified Viewed 8,269 times
S
stinky
S
stinky 10
  • Newbie, joined since
  • Contributed 3 posts on the community forums.
  • Started 1 thread in the forums
  • Started this discussions
asked
Newbie

Today i logged into admin panel and I found something disquieting. There was new panel on my panels list called "System". I looked in database to check it, the panel code was:


And there was a javascript in site source code:


Version is 6.01.19.
I guess it's encoded by base64, but I can't decode it. Any ideas?

Mod: Removed hacker code from public view
Edited by HobbyMan on 12-06-2010 13:15,
0 replies

7 posts

C
Craig
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
answered
Fusioneer

I am sorry to hear that, lets try and find out how they achieved it.

Can you please follow these steps and provide the info?

1. Go to PHPMyAdmin and disable all the panels manually.

To do this go into your DB in PHPMyAdmin and look for the table...

fusion_panels select "Browse" and you will now see all your panels.

Disable them all by editing each one Change panel_status for all to 0 and save.

2. Now go to your site and turn on Maintenance Mode.

3. Change your Password and all Admin Passwords

4. Change FTP & All SQL Password and other Host related passwords just to make sure.




Now what we need to know is....



a.What exact version of PHPFusion are you running?

b. What Mods/ Infusions/ Panels were you using?

c. Do you know the estimated time this hack happened?

d. Do you have Access Log for roughly the last 24 hours you can provide or check yourself?

e. Do you have any other info we should know?
0 replies
S
stinky
S
stinky 10
  • Newbie, joined since
  • Contributed 3 posts on the community forums.
  • Started 1 thread in the forums
  • Started this discussions
answered
Newbie

I have already changed all passwords and removed panel from db.

a.What exact version of PHPFusion are you running?
6.01.19 (I guess I put this thread in a wrong section)

b. What Mods/ Infusions/ Panels were you using?
IP Polls, News Archive, Slideshows Random Photo Panel
and my own friendly URL mod (htaccess).

c. Do you know the estimated time this hack happened?
Unfortunately no. It could have happened a pretty long time ago. One of my users told me today, that his antivirus blocks this script.

d. Do you have Access Log for roughly the last 24 hours you can provide or check yourself?
I got it, but in my opinion there's nothing unexpected.

e. Do you have any other info we should know?
I had some DoS attacks recently.
Edited by stinky on 11-06-2010 16:38,
0 replies
C
Craig
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
answered
Fusioneer

Do you know the IP of the Hacker?
0 replies
S
stinky
S
stinky 10
  • Newbie, joined since
  • Contributed 3 posts on the community forums.
  • Started 1 thread in the forums
  • Started this discussions
answered
Newbie

Nope.
0 replies
C
Craig
C
Craig 14
  • Fusioneer, joined since
  • Contributed 4,462 posts on the community forums.
  • Started 212 threads in the forums
answered
Fusioneer

Upgrade to the latest Version of PHPFusion V7, V7 rocks.

Look through all your folders for suspicious files.
Edited by Craig on 13-06-2010 03:07,
0 replies
A
aviator77
A
  • Newbie, joined since
  • Contributed 1 post on the community forums.
answered
Newbie

it's best to keep on changing passwords of using special characters of all admin panels.
0 replies
M
MvE Designs
M
  • Junior Member, joined since
  • Contributed 49 posts on the community forums.
  • Started 1 thread in the forums
answered
Junior Member

Please transfer to PHPFusion 6 Support
0 replies

Labels

None yet

Statistics

  • Views 0 views
  • Posts 7 posts
  • Votes 0 votes
  • Topic users 4 members

0 participants

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet