WTF

Post non-phpwcms related topics here - but I don't want to see "hey check this or that other cms". Post if you have a point or worthwhile comment, don't post just to increase you post count!
Post Reply
GNU1516
Posts: 2
Joined: Wed 28. Dec 2005, 11:44

WTF

Post by GNU1516 »

what the crap, our site was hacked, and linked here. just thought i'd let you know.
User avatar
Fulvio Romanin
Posts: 394
Joined: Thu 4. Dec 2003, 11:12
Location: Udine, Italy
Contact:

Post by Fulvio Romanin »

which site?
it's so weird, please give us some hint...
unless you didn't try to install wcms and to run it without installing the db, which sends here...
Completeness is reached through subtraction, not through addition
frold
Posts: 2151
Joined: Tue 25. Nov 2003, 22:42

Re: WTF

Post by frold »

GNU1516 wrote:what the crap, our site was hacked, and linked here. just thought i'd let you know.
sry cant take that serious without more details...

I could be your server that aint safe == not a phpwcms issue...
http://www.studmed.dk Portal for doctors and medical students in Denmark
GNU1516
Posts: 2
Joined: Wed 28. Dec 2005, 11:44

Post by GNU1516 »

our site is yellowlaser.net, and this is the second time we got hacked.
frold
Posts: 2151
Joined: Tue 25. Nov 2003, 22:42

Post by frold »

GNU1516 wrote:our site is yellowlaser.net, and this is the second time we got hacked.
But it first time anyone say so, so I guess it a server issue and not a phpwcms - we need more evidence
http://www.studmed.dk Portal for doctors and medical students in Denmark
Ben
Posts: 558
Joined: Wed 14. Jan 2004, 08:05
Location: Atlanta
Contact:

Post by Ben »

Did your site even use phpWCMS? It seems that if there were problems connecting to the database, it might forward visitors to http://www.phpwcms.de/dbdown.php
Last edited by Ben on Thu 29. Dec 2005, 00:56, edited 1 time in total.
User avatar
DeXXus
Posts: 2168
Joined: Fri 28. Nov 2003, 06:20
Location: USA - Florida

Post by DeXXus »

Is this possibly an install attempt of phpWCMS? The "appearance" of your site going to http://www.php.de can occur if:
new user doesn't "save" the "config.inc.php" file generated during setup and instead the default "conf.inc.php" from initial install remains:

Code: Select all

// site values
$phpwcms["site"]              = "http://www.phpwcms.de/";
User avatar
Fulvio Romanin
Posts: 394
Joined: Thu 4. Dec 2003, 11:12
Location: Udine, Italy
Contact:

Post by Fulvio Romanin »

might be a server issue... i hope... :shock:

anyway we'd need proof that wcms was hacked, and it's pretty hard to understand how you could possibly have a whole server hacked on mere db connection values, since usually there's no root access or whatever in the wcms config....

do you have any other evidence it was wcms's fault?
Completeness is reached through subtraction, not through addition
Post Reply