Login
Username

Password



Not a member yet?
Click here to register.

Forgotten your password?
Request a new one here.
Navigation
Latest Addons
AD Gallery 44
SyntaxHighlighte... 48
Newsletters v4.03 106
Facebook Like Box 122
Newsletters v4.02 56
Metro 153
Facebook Connect 166
Shoutbox Panel 125
Redactor for PHP... 104
MI Floating Side... 106
Facebook Login/R... 149
Avatar Studio v2.03 177
Relationship Sta... 96
Sexual Orientati... 113
Fisherman 140
Popular Addons
iTheme2 5796
Arise 5783
User Control v1.23 4616
Event Calendar 4045
Photowidget panel 3884
Radio-Theme red2... 3350
Highslide Gallery 3311
CSS/JavaScript D... 3223
Facebook Connect... 2979
Dynamic Menu 2889
Slideshow Lightb... 2719
L-AMANT 2656
Enigma 2629
2Dark 2603
Black 2571
View Thread
Who is here? 1 guest(s)
 Print Thread
my school website has been hack
amex
my school website has been hack.. the hacker was send this message...

"this website vulnerable for sql injection method..please patch your site.. i've been upload my backdoor using tamper data "...

what should i do next...
help please...
 
kneekoo
Hello. The first thing you need to do is to backup everything (files and MySQL database), clean up all your files from your webserver and install the latest PHP-Fusion version and put it in maintenance mode on your website. The core itself doesn't have any known vulnerabilities so this will be a good start.

Next, spend some serious time identifying and making the list of all the extra components you installed on your PHP-Fusion site. It's most likely one of them responsible for the vulnerability. Of course, you should also make sure you don't have other scripts on your website. Some people use several scripts on their domains and in such cases it will be very hard to identify the culprit without server logs.

The message says you have a backdoor uploaded on your site. This is most likely a php file, so you will have to look for any php file that doesn't belong to PHP-Fusion. It isn't easy, but you'll have to do it, or at least ask someone else to look for it, because you have to identify and eliminate two things:

1. The backdoor
2. The vulnerable add-on
 
http://www.phpfusion.ro/
amex
i was checked the modification date of all the file... and i dont find any file that was modified on the date and time he/she login.... is't a joking or what...

Merged on May 11 2012 at 07:17:22:
i have the hackers IP, email n her/his web site.
"124.13.182.15"

qreyzee1813(@)gmail.com
fiqri1813(@)yahoo.com
http(://www).h4ck1ngw1thf1qr1.com
remove ()

what should i do next... i just delete my sql database and restore back from my backup...
Edited by amex on 11-05-2012 07:20
 
skpacman
Either the "hacker" is trolling you, or you were actually hacked.

kneekoo pretty much hit the nail on the head for instructions.

Put your site in maintenance mode, check all files, check your DB, disable all addons, delete bad content, etc...

Are you sure you didn't see any extra files that you didn't put there? (maybe in another directory?)
 
http://www.php-fusion.us
Ugleh
you cant upload a file through sql injection.
 
ugleh.com
amex
i was checked all the file in public html... there are no file that have been modified on 10/5/2012 (the day he/she said he upload a backdoor)...
 
kneekoo
The backdoor could have been uploaded previously so you should rather check for modified files during the last week or even month. But for your safety you should check everything. It's a school website, so it does matter. You won't look good if someone steals and publishes anything from your website, so take your time and do the right thing for your own sake.

@Ugleh: The so-called hacker didn't say he uploaded a backdoor through an SQL injection but if certain add-ons are not well protected using the core functions you can end up offering hackers the opportunity of injecting MySQL code that changes the allowed attachment types in PHP-Fusion, then upload a PHP script as the backdoor and even change the allowed file-types back to normal, so nothing looks strange to the admins.
 
http://www.phpfusion.ro/
Jump to Forum:
Similar Threads
Thread Forum Replies Last Post
Profile Misc. Info. Website https BUG Suspected Bugs and Errors 16 10-05-2013 13:21
website crash User Administration 7 31-03-2013 12:17
Another website PF7 Post Your Site 10 07-03-2013 00:21
Regarding My website Themes Support 1 12-02-2013 16:05
Reinstall website Installation Issues 7 04-01-2013 15:10
Official Home of PHP-Fusion uses cookies. Some may already have been set. Read more about our Cookies here.
Please click the button I Consent Cookies to hide this bar and accept our cookies. If you continue to use the site with no action taken, we'll assume that you consent our cookies anyway.
Cookiebar Panel byVenue