Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Hacked again!!!!
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  14:47:17  Show Profile
New hack, seems to be in the js scripts some where!!!!

http://www.sasportscar.com

weeweeslap
Senior Member

USA
1077 Posts

Posted - 04 January 2008 :  14:49:33  Show Profile  Visit weeweeslap's Homepage  Send weeweeslap an AOL message  Send weeweeslap a Yahoo! Message
how do you conclude this was done through the forum and not through your ftp. The link indicates files were placed on your home page. and not the forum directory.

coaster crazy
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  14:53:05  Show Profile
There is only one file on home page that redirects to forum. No FTP up and running.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  14:56:33  Show Profile  Send ruirib a Yahoo! Message
Have you applied the December 1st Security Fixes?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  14:57:18  Show Profile
I found some edits in my DB.
in the config_new table

STRFORUMTITLE "<script>document.location=""http://e-protest.net/hacked/""</script>"
STRCOPYRIGHT"<script>document.location=""http://e-protest.net/hacked/""</script>"

Edited by - Red01Z06 on 04 January 2008 14:58:18
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 04 January 2008 :  14:58:15  Show Profile  Visit MarcelG's Homepage
It's an SQL injection in the forum title:
<title><script>document.location="http://e-protest.net/hacked/"</script></title>

[edit]What Red said, I was too late.

Red, do you have the PM mod installed, or do you have other (old) mods installed? They have come in somewhere via a SQL injection, ór they have gained access to your (or the admin's) account.

Please check your serverlogs, and check if something can be made up from there, as to how they came in.

portfolio - linkshrinker - oxle - twitter

Edited by - MarcelG on 04 January 2008 15:00:39
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  14:59:51  Show Profile
best way to patch, clean? I removed those edits.....site stil down.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  15:01:51  Show Profile  Send ruirib a Yahoo! Message
You will need to apply the December 1st fixes in active.asp. Then visit down.asp?mlev=4 and get the forum up.

Once the forum is up, remove any admins that should not be there.

Don't forget to subscribe to the Announcements Security Related Bug Fixes forum.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 04 January 2008 :  15:01:57  Show Profile  Visit MarcelG's Homepage
Red, the copyright thing is still the script....that's keeping you getting redirected to the hackers site.

portfolio - linkshrinker - oxle - twitter

Edited by - MarcelG on 04 January 2008 15:02:11
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:04:04  Show Profile
That patch was done after first hack. I canot visit down.asp as it sends me to hacked site.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  15:05:48  Show Profile  Send ruirib a Yahoo! Message
You will probably not be able to get down.asp to work. You will need to edit the values from forum_config_new to stop the hacking.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:09:44  Show Profile
I edited that table, but hack still there....where else should I look?
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 04 January 2008 :  15:11:59  Show Profile  Visit AnonJr's Homepage
Its also worth re-asking Marcel's question: do you have any MODs installed (or custom code, or anything other than a clean install)? It will help us figure out how you got hacked after applying the patch.

Edited by - AnonJr on 04 January 2008 15:12:49
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:15:25  Show Profile
Alot of mods, started with the Imagageforum version.
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:18:20  Show Profile
I beleave the hacker came from this IP
88.235.78.31

fyi
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 04 January 2008 :  15:18:40  Show Profile  Visit HuwR's Homepage
if you can get hold of your web servers log files around the time the hack happened that is the best place to start looking, you can email me th log file if you would rather someone else looked
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.46 seconds. Powered By: Snitz Forums 2000 Version 3.4.07