SnippetMaster Support Forums
Return to main website
 
September 17, 2009, 11:38:10 PM
* Show unread posts since last visit.
* Show new replies to your posts.
Welcome, Guest. Please login or register.
Did you miss your activation email?
September 17, 2009, 11:38:10 PM

Login with username, password and session length
Search:  
Advanced search
* Home Help Search Login Register
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: Pro Install Continually Hacked « previous next »
Pages: [1] Print
Author Topic: Pro Install Continually Hacked  (Read 779 times)
Cobla

Posts: 12


[-] Pro Install Continually Hacked
« on: December 04, 2007, 02:56:55 PM »

One of my Pro installs (v2 of course) is being hacked on a daily basis and I'm getting sick of re-installing every single morning so here I am! Wink

The hack in question seems to just be inserting bad code into index.php however because this bad code is neither IonCube or Zend encoded Snippetmaster returns with the message "index.php is corrupted" and I have to re-install.

I got in touch with my web host who informed me to reduce file permissions (index.php is already 644 anyway!) and to remove / repair the PHP code that is allowing the hacks to take place.

"Fixing" SnippetMaster is way out of my scope (even if the PHP files weren't encoded) so I really don't know what to do, other than change web host of course...

Any ideas?

Thanks!! Very Happy
Report to moderator   Logged
Jenkinhill
Beta Tester

Posts: 389



[-] Re: Pro Install Continually Hacked
« Reply #1 on: December 05, 2007, 01:14:38 AM »

How is this "hacking" taking place? Does someone else have admin/super access to SnippetMaster so they can edit whole files? Or ftp access to the server? Access via server control panel? First step when something like this happens is to change all passwords. Then look for other scripts on your own site which could be hacked or provide access for hackers, such as old forum programs - or even on the server if you are on a poorly configured shared host.  In any case, it may be useful to check the server logs carefully to see when/if there are accesses other than your own to the SnippetMaster directory.

If I were a hacker of SnippetMaster I would not be interested in altering index.php - I'd be putting advertising on your web pages!

The index file does not need to be writable at all, and chmod to 444 may work for you.
Report to moderator   Logged

Kelvyn
Cobla

Posts: 12


[-] Re: Pro Install Continually Hacked
« Reply #2 on: December 05, 2007, 02:11:11 PM »

Thanks for the advice - much appreciated! Smile

The attacks on the site were originally thought to be via old PHP scripts (that's what the web host said at least). On closer inspection however, it was actually by FTP so I've changed all my passwords and *fingers corssed* won't have any more dramas.

Thanks again. Smile

Colby
Report to moderator   Logged
Pages: [1] Print 
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: Pro Install Continually Hacked « previous next »
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!