Nuke Toolbar

          
Quick Links 
 [Home Page ][ Category Listings ][ Forum Listings][ Forum FAQs]
[ HomeDNS - Domains ]  [ Nuke Resources ]  [ Nuke Skins and Themes ]  [ Nuke Sites Link Directory ]
[ LearningLinux.com ]  [ Nuke Fixes ]
[ NukeZone Hosting ]  [ Domain Name Database ]
Nuke Forums Forum Index

Nuke Sites Link Directory


Hacked - what do I do?

 
Post new topic   Reply to topic    Nuke Forums Forum Index -> PHP Nuke Security
View previous topic :: View next topic  
Author Message
stevelamb
Guest






PostPosted: Mon Mar 31, 2003 1:56 am    Post subject: Reply with quote

We've been hacked twice now in the last week. First time they added a new story on the home page - an anti-war message. The second time an anti-war message again, but this time replacing an existing story. How are they doing this and what can I do to stop it? We have .htaccess on our phpMyAdmin and we're not hosting ourselves - we use a web host.

We're using phpnuke 5.6 and have modified many parts of it so can't really upgrade.

thanks
Back to top
chatserv
President
President


Joined: 19 Aug 2001
Posts: 3258


PostPosted: Mon Mar 31, 2003 6:54 am    Post subject: Reply with quote

http://www.nukeforums.com/downloads/phpNuke_5.6/BUGS.txt
Back to top
View user's profile Send private message Visit poster's website
stevelamb
Guest






PostPosted: Mon Mar 31, 2003 7:35 am    Post subject: Reply with quote

Hi

Thanks for quick reply.

Is it just that first bug fix, the change to line 35 in index.php? can you explain to me what it means?

thanks again
Back to top
chatserv
President
President


Joined: 19 Aug 2001
Posts: 3258


PostPosted: Mon Mar 31, 2003 8:59 am    Post subject: Reply with quote

The hack that was being used to alter site stories basically converted the $score variable into a sql command to alter story titles and content, adding a integer value check to the score variable attempts to make sure nothing besides a score value is used.
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Nuke Forums Forum Index -> PHP Nuke Security All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group




Forum Options
Main Menu
index.phpForums Index
    - Collaped View
    + Expanded View
FAQFAQ
SearchSearch
MemberlistMemberlist
UsergroupsUsergroups
RegisterRegister
ProfileProfile
Log in to check your private messagesLog in to check your private messages
Log inLog in

Visitor Options
 
Subscribe
Unsubscribe


Keep informed of updates, bug fixes, software releases, news and more!
Installation or Upgrade Services for phpNuke or PostNuke? Require site maintenance, addons, modules or custom themes? Send private message or e-mail for rates and availablity.

Quick Links
  Domain Names
  Firewall Forums
  Joke Crazy
  Learning Linux
  Find your IP Fast!
  Purchase WinRAR

Trusted Nuke Sites
  NukeZone Hosting
  CMS Focus
  NukeFixes.com
  NukeResources.com
  NukeSkins.com
  NukeSites.com
  PHPNuke.org

Sponsor Links


NukeZone Hosting