Shoutbox

My site's guestbook/msg board has been hacked. can anyone help? - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: My site's guestbook/msg board has been hacked. can anyone help? (/showthread.php?tid=58611)

My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-22-2006 at 08:52 AM

hey there,
I just went to have a look at my site's message board (http://wetpix.ceejaycee.net/viperguestbook/)
and a different page comes up.
I can get into the administration and control and all entries etc are still there. i just cant view the actual page.
My website is only a small site to show my photos taken of myself and friends bodyboarding etc. Must make the person feel real big to be able to hack it...
Anyway any help or suggestions on how i can get it back to normal?
Thanks guys


RE: My site's guestbook/msg board has been hacked. can anyone help? by Funness on 04-22-2006 at 08:56 AM

Because of sites like "zone-h.org" all the kiddies want to make their ego bigger by having more sites under their name. No matter have small and pointless the site is.

Chances are your content script was not up-to-date.

What content/admin software do you use?



I would suggest you back up your database and reinstall it.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Stigmata on 04-22-2006 at 09:16 AM

can you show us what files are in the viperguestbook directory??


like how is the guestbook set out??


ps: ive taken the liberty of disabling his msn address..


RE: My site's guestbook/msg board has been hacked. can anyone help? by John Anderton on 04-22-2006 at 10:20 AM

quote:
Originally posted by Funness
What content/admin software do you use?
quote:
Originally posted by Dan0208
(http://wetpix.ceejaycee.net/viperguestbook/)
8-)
:dodgy:
RE: My site's guestbook/msg board has been hacked. can anyone help? by DJeX on 04-22-2006 at 07:45 PM

Bah I'm getting sick of these wimpy hacks that these so called Islamic hackers are doing on sites. My forum got hacked in the same way. Just remember to keep all your stuff updated.\

I'll take a look to see if I can help you out here.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Chris4 on 04-23-2006 at 12:13 AM

Can I just ask, how do you know it's been hacked? Because all I get is a 404 error page and that can happen for multiple reasons.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Funness on 04-23-2006 at 12:22 AM

Its 403  now, but it was a replaced index file with really crappy music.

Iy is 404ing, but thats just because it can not find an errorpage.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Jhrono on 04-23-2006 at 12:38 AM

quote:
Originally posted by Chris4


Can I just ask, how do you know it's been hacked? Because all I get is a 404 error page and that can happen for multiple reasons.
There was a thing saying

'Hacked by <insert hacker's name here>'
RE: My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-23-2006 at 02:06 AM

Yes now it only goes to an error page but before it had a changed page with a stupid skull and the "hacker's" name.
I have just tried to access the viperguestbook directory via ftp and I cannot see inside it as now i do not have permission?? see below screenshot.

Also i can no longer access the online adminstration which was at http://wetpix.ceejaycee.net/viperguestbook/admin.php
I could do that yesterday before the error page.

Can anyone lend a hand here this is really annoying and i had alot of entries from friends, family etc that I would like to restore.

Thanks for the help so far guys


UPDATE: I just changed the permissions to the folder myself and i can now get in and look at the files within the directory via ftp. here is a shot of what it contains if it can help anyone.
[Image: viperdirectory8oe.th.jpg]


RE: My site's guestbook/msg board has been hacked. can anyone help? by Funness on 04-23-2006 at 03:08 AM

Did your guestbook have an uploader script? Those are very open to hackers.

Check the CHMOD of your folder/files. Set admin.php to 755.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-23-2006 at 04:09 AM

I dont think it had an uploader script unless it was on by default.
Javascript was enabled though so maybe that could have allowed things to go on.

I just changed permission to 755 on admin.php which is
Owner permissions: Read Write Execute
Group Permissions: Read Execute
Public Permissions: Read Execute

however I still cannot access it. Im pretty sure my version was up to date as well as im using v1.2 FINAL and thats the most recent on the website.
in the viperguestbook directory there is no longer a index.php file. Does that mean it has been removed by the loser "hacker"?

Is there a way I can maybe 'repair' the install as to keep all entries and database info etc but fix this all up?

Thanks for the help so far


RE: My site's guestbook/msg board has been hacked. can anyone help? by Funness on 04-23-2006 at 04:14 AM

Try reuploading the index.php. Most likely their was no information been stored in the index.php and just uploading it again will have no ill effect on your site/data.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-23-2006 at 04:19 AM

How do I re-upload it when I dont have it? it was all installed when I setup the guestbook.


RE: My site's guestbook/msg board has been hacked. can anyone help? by Adeptus on 04-23-2006 at 04:32 AM

quote:
How do I re-upload it when I dont have it? it was all installed when I setup the guestbook.
Solution 1: set it up again, however you do that.  It worked before, it will work again.

Solution 2: if you have any idea what the name of the guestbook script was, Google (or someone here) could help you find it and you could only extract and upload the files you need.
RE: My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-23-2006 at 04:50 AM

Ok I managed to find *by chance* an old index.php that I had on an old hard drive that I was once using when I was editing the style, skin etc.
So I uploaded that and that was fine. One more thing I had to do was change the permissions on every single little file, including all little images, so they were back viewable again.

To cut it short I managed to get it back up and running again. Can anyone offer any suggestions on how I can prevent this happening again as it was quite a hassle.
There is an upload folder in the viperguestbook directory I just noticed so i've changed the permissions on that to hopefully only make it viewable by the owner. Anything else you can think of?

Once again thanks for the help everyone.


RE: My site's guestbook/msg board has been hacked. can anyone help? by WDZ on 04-23-2006 at 04:51 AM

quote:
Originally posted by Dan0208
Im pretty sure my version was up to date as well as im using v1.2 FINAL and thats the most recent on the website.
I went to www.vipergb.de.vu and it says version 1.2 is "No longer updated!" :p
RE: My site's guestbook/msg board has been hacked. can anyone help? by Dan0208 on 04-23-2006 at 05:05 AM

yea I know. thats why I said its the most recent version on the website.
I would assume 1.2 FINAL is newer than X1?


RE: My site's guestbook/msg board has been hacked. can anyone help? by Adeptus on 04-23-2006 at 05:02 PM

http://mitglied.lycos.de/vipergb/indexx1.php

quote:
Upgrade to X1.0
from 1.2 FINAL or X1.x
It would appear that X1.0 is newer.  :P