You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 139 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - nuke_config Table Modified [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
DivotMaker
Nuke Soldier
Nuke Soldier


Joined: Sep 05, 2004
Posts: 29


PostPosted: Tue Nov 23, 2004 2:04 pm Reply with quoteBack to top

A few days ago, users starting reporting viruses when they went to my PHP 7.3 site. Sure enough, there was some sort of redirect going on that would try and open a porn site in a small window when any page was loaded on my site. I was able to isolate the problem to footer.php, then further isolate it to the copyright$ variable. I looked up the copyright field in my nuke_config table, and it was modified by someone other than me and included some code to load a porn site. I am the only admin for our site, so I've ruled out an unhappy admin changing the field. The only 2 options I came up with is someone either hacked into my web host's server, or someone logged into My PHP Admin account and did the change there. I'm running Nuke Sentinel on my site too. I did change my passwords, but was wondering if there's anything else I should look into. I wasn't sure if I should paste the contents of my hacked "copyright" field or not. If it's okay, I will do so if someone thinks it will help. Thanks.
Find all posts by DivotMakerView user's profileSend private message
HalJordan
Support Staff
Support Staff


Joined: Aug 07, 2004
Posts: 1117

Location: Somewhere around Hunan, China

PostPosted: Tue Nov 23, 2004 8:02 pm Reply with quoteBack to top

PM it to me and I will take a look at it.

While Sentinel is good, I also run AdminSecure, which helps prevent admin account hacking. You should also get the patched 7.3 files available at nukefixes.com, which prevent SQL injection attacks, like the one you describe.

Finally, if we can trace the source of the injection you should block that IP or IP range from accessing your site.

_________________
Obedezco, pero no cumplo.

Proprietor, www.computernewbie.info
Support staff, www.nukecops.com
Find all posts by HalJordanView user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.588 Seconds - 133 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::