|
My site is hacked again :(
|
| leszcz33 |
Posted on 22-10-2011 13:48
|

Newbie

Posts: 9
Joined: 22/10/2011
|
Welcome. please help from you. My site was attacked again by putting strange code of PHP code. Sorry for English. it looks like this:
Code<?php eval(base64_decode("ZXJyb3JfcmVwb3J0a - part of code removed due to security reasons "));
Unfortunately, colleagues from the Polish forum posts and cancel my account blocked me. Looking for help to protect against attacks.
Forum is here to help each other and not just to closing down the account. Not everyone is a guru of fusion. I think we should help each other. Polish colleagues can only ban. Unfortunately this is strange.
Additionally, in my current post entered a hidden message. This is sad: (
thanks leszcz33 of Polish
Edited by leszcz33 on 22-10-2011 19:13
|
| |
|
|
| PolarFox |
Posted on 23-10-2011 00:15
|

Admin

Posts: 1503
Joined: 26/08/2008
|
It was only index.php, or another files was corrupted too?
|
| |
|
|
| leszcz33 |
Posted on 23-10-2011 17:52
|

Newbie

Posts: 9
Joined: 22/10/2011
|
all php files  |
| |
|
|
| PolarFox |
Posted on 23-10-2011 19:57
|

Admin

Posts: 1503
Joined: 26/08/2008
|
Wrong permissions on all files, or you have got a trojan inside your pc.
|
| |
|
|
| leszcz33 |
Posted on 23-10-2011 20:48
|

Newbie

Posts: 9
Joined: 22/10/2011
|
PolarFox wrote:
Wrong permissions on all files, or you have got a trojan inside your pc.
No my computer is free . Protected with NIS2012 and all permission is good.
I change all passwords ; FTP and passwords for site and wait what happend  |
| |
|
|
| krystian1988 |
Posted on 23-10-2011 20:54
|

Newbie

Posts: 4
Joined: 03/11/2010
|
Error because you have Total Commander in the earlier version, which is dangerous to use users. |
| |
|
|
| leszcz33 |
Posted on 26-10-2011 19:07
|

Newbie

Posts: 9
Joined: 22/10/2011
|
krystian1988 wrote:
Error because you have Total Commander in the earlier version, which is dangerous to use users.
No i dont use TotalCommander
I still have a problem . Please help
Still haks my site . |
| |
|
|
| hoopak |
Posted on 26-10-2011 19:42
|

Newbie

Posts: 1
Joined: 29/12/2008
|
Which version of PF you've got?
|
| |
|
|
| Craig |
Posted on 26-10-2011 19:53
|

Fusioneer

Posts: 3980
Joined: 27/09/2005
|
A site link would be handy? |
| |
|
|
| leszcz33 |
Posted on 26-10-2011 19:58
|

Newbie

Posts: 9
Joined: 22/10/2011
|
7.01.06 |
| |
|
|
| leszcz33 |
Posted on 26-10-2011 20:06
|

Newbie

Posts: 9
Joined: 22/10/2011
|
http://dolaczdona...kolaku.org
This page about children and kindergarten ......... I am surprised an attack on such a page.
Now the site is inactive. Server administrators trying to determine the source of attacks.
I have no idea last attack was online and append the code for "my eyes"
I do not have viruses and do not use any TotalCommander.
Changing passwords gave nothing.
On the server, two files have written yet phpinfo.php and phpinfo.php5 do not know where I placed them there
Edited by leszcz33 on 27-10-2011 17:14
|
| |
|
|
| PolarFox |
Posted on 26-10-2011 22:50
|

Admin

Posts: 1503
Joined: 26/08/2008
|
What plugins/mods do you have?
btw try this http://www.freedr...it/?lng=en also
|
| |
|
|
| leszcz33 |
Posted on 27-10-2011 07:48
|

Newbie

Posts: 9
Joined: 22/10/2011
|
standart plugins/mods I have |
| |
|
|
| PolarFox |
Posted on 27-10-2011 15:24
|

Admin

Posts: 1503
Joined: 26/08/2008
|
Can you send me your logs from the server?
|
| |
|
|
| leszcz33 |
Posted on 27-10-2011 17:19
|

Newbie

Posts: 9
Joined: 22/10/2011
|
My server provider changed. I now have a different IP. Page works ok so far
what logs should I send? |
| |
|
|
| PolarFox |
Posted on 28-10-2011 07:54
|

Admin

Posts: 1503
Joined: 26/08/2008
|
Access logs, error logs , if you have it.
|
| |
|
|
| hien |
Posted on 29-10-2011 02:40
|

Admin

Posts: 177
Joined: 25/09/2007
|
I have been using phpfusion for last 6 years, and the security fixes has been better and better. all you dev remember to use access security check before processing any $_post or $_get function. addslashes to all text boxes and it will be fine. the main core.php is so far much superior to joomla.
|
| |
|
|
| leszcz33 |
Posted on 07-11-2011 10:47
|

Newbie

Posts: 9
Joined: 22/10/2011
|
My site working good when my provider change serwer and IP |
| |
|