v1.3.3 Constantly being hacked...

Get help with installation and running phpwcms here. Please do not post bug reports or feature requests here.
Post Reply
C3 Motorsport
Posts: 7
Joined: Thu 17. Mar 2005, 18:31
Location: San Jose, CA
Contact:

v1.3.3 Constantly being hacked...

Post by C3 Motorsport »

For some reason, I don't know if I'm being targeted or what the deal is, but every single one of my websites on my server running phpWCMS version 1.3.3 has been hacked, and it seems to be happening more frequently.

It started off about 6 months ago by some prick named UltraTurk, and now some guy called Asl_PaRdOnE, part of some Turkish hacker group and some other jerk that calls himself SenqRonize.

The only thing that ever gets modified is the index.php file and nothing else. The database, and all other phpWCMS files are intact.

Does anyone have any advice for me? How can I keep these sites from getting hacked? What is the security problem with the index.php file? The only solution I have is to just overwrite the index.php back to the original file to get the site back, but then it just gets hacked again.

I have about 15-20 sites on the same server, and other CMS systems like Mambo, flash-based, and hard-coded haven't been touched. So is someone targeting phpWCMS sites?

Please HELP!

Sites affected:

http://www.5-75.org
http://www.jason-steele.com
http://www.c3motorsport.com (fixed)
http://www.blackwidowproject.com (fixed)
- Jason

C3 Motorsport: BMW Tuning & Accessories
http://www.c3motorsport.com
User avatar
DeXXus
Posts: 2168
Joined: Fri 28. Nov 2003, 06:20
Location: USA - Florida

Post by DeXXus »

If ONLY index.php is changed...what "changes" EXACTLY occur? What does a "file compare" show? Just curious.
C3 Motorsport
Posts: 7
Joined: Thu 17. Mar 2005, 18:31
Location: San Jose, CA
Contact:

Post by C3 Motorsport »

The index.php is completely re-written. As if someone copied a new index.php in its place. No resemblance of the original file. The only one that appears to have some resemblance of the original file is the index.php on 5-75.org . I'll do a **** in a little while when I get home.

What I'm trying to get to the bottom of is whether or not there is a security bug in the index.php file and if there is, is that what is giving them access to the file to change it?

Don't get me wrong, I absolutely love everything about phpWCMS, but if this continues to happen, I may end up looking for another, more secure application. the 5-75.org is a site I'm developing for a US Army unit, and the last thing they can afford is to have their site HACKED. Fortunately, it hasn't gone live yet.
- Jason

C3 Motorsport: BMW Tuning & Accessories
http://www.c3motorsport.com
sunburn
Posts: 46
Joined: Wed 2. Mar 2005, 12:13

Post by sunburn »

...


http://www.5-75.org/login.php

ACHTUNG! Das "SETUP" Verzeichnis ist noch immer vorhanden! Löschen Sie dieses Verzeichnis, sonst haben Sie ein potentielles Sicherheitproblem.

delete your setup-folder .... may this will help ...

greets
sunburn
User avatar
sustia
Posts: 651
Joined: Fri 2. Apr 2004, 22:29
Location: Lecce (Italy)
Contact:

Post by sustia »

sunburn wrote:...



delete your setup-folder .... may this will help ...

greets
sunburn
And trying to do a setup everyone is able to read the data of DB user, DB password and DB database...
Campeones del mundo!
Vegetables!
User avatar
pico
Posts: 2595
Joined: Wed 28. Jul 2004, 18:04
Location: Frankfurt/M Germany
Contact:

Post by pico »

What's up, good People?

seems that your Server is NOT save at all :twisted: :evil:
Lieber Gott gib mir Geduld - ABER BEEIL DICH
Horst - find me at Musiker-Board
User avatar
DeXXus
Posts: 2168
Joined: Fri 28. Nov 2003, 06:20
Location: USA - Florida

Post by DeXXus »

:arrow: YUP, first two sites in list are still vulnerable! :o
Post Reply