Congratulations to AcaCandy on her 100,000th post!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer black screen blue screen boot bsod computer connection crash css dell driver drivers email error ethernet excel firefox firefox 3 game hard drive internet internet explorer itunes laptop linux malware monitor network networking nvidia outlook outlook 2003 outlook 2007 outlook express partition problem router slow software sound trojan usb video virus vista wifi windows windows vista windows xp wireless
Web Design & Development
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Internet & Networking > Web Design & Development >
Website infection


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
Xearoveg's Avatar
Junior Member with 28 posts.
 
Join Date: Dec 2005
10-Jun-2007, 03:38 PM #1
Website infection
I have a forum on my webserver and it recently got attacked by some russian hackers.

I have another thread about what happens when someone views the phpbb forum in IE. They generally get infected with a virus of sorts that causes this: http://forums.techguy.org/security/5...ml#post4800559

I wiped all domains on my webserver and reuploaded phpbb from scratch, then my templates, and then my db backup. It then is re-infected within 1-2 days. When I don't put in the db backup it seems it won't get infected.

So my question is, is there a way to clean or sort through my database backup and be able to salvage it? There is a lot of posts and such I don't want to lose. I can post it if needed. I don't know if there is anything in it I should not post or sensor, like pws or something hidden in there.
Xearoveg's Avatar
Junior Member with 28 posts.
 
Join Date: Dec 2005
11-Jun-2007, 10:39 AM #2
bump
Xearoveg's Avatar
Junior Member with 28 posts.
 
Join Date: Dec 2005
11-Jun-2007, 02:25 PM #3
I'm going to upgrade and convert my forums to phpbb3 and see if that does the trick. Sounds promising.
cpscdave's Avatar
Senior Member with 281 posts.
 
Join Date: Feb 2004
Experience: Intermediate
11-Jun-2007, 03:54 PM #4
I dont know of any examples specifically but I have heard in 2-3 different locations that there are security holes in phpbb. Best bet is to upgrade to lateset version (like you say you are going to) otherwise they'll just keep on exploiting the security hole and changing your stuff.
__________________
Its not a bug.... Its a feature!

Programming today is a race between software engineers striving to build bigger and better idiot-proof
programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning.
-Rick Cook

Spam a problem for you? http://spamooze.com
Xearoveg's Avatar
Junior Member with 28 posts.
 
Join Date: Dec 2005
11-Jun-2007, 04:02 PM #5
Thanks, I think it'll work too. Glad someone finally posted to at least one of my threads.
cpscdave's Avatar
Senior Member with 281 posts.
 
Join Date: Feb 2004
Experience: Intermediate
11-Jun-2007, 04:11 PM #6
Hehehe sometimes it takes a while others it goes quickly.

*just another note:

To anyone who uses open source items/frameworks whatever. You should always keep the code up-to-date as anyone can see the code they have a lot easier time finding vulnerbilities in the code.

Oh... AND ALWAYS ALWAYS ALWAYS change the default password
__________________
Its not a bug.... Its a feature!

Programming today is a race between software engineers striving to build bigger and better idiot-proof
programs, and the Universe trying to produce bigger and better idiots. So far, the Universe is winning.
-Rick Cook

Spam a problem for you? http://spamooze.com
Xearoveg's Avatar
Junior Member with 28 posts.
 
Join Date: Dec 2005
13-Jun-2007, 06:12 PM #7
Wow it didn't work, they hacked it again.
aewarnick's Avatar
Senior Member with 839 posts.
 
Join Date: Sep 2002
16-Jun-2007, 09:19 AM #8
They must have something against you.
What is the link to your site?
Are you sure it's phpbb they're exploiting?
Is your site running on Linux or Windows?
dragjack's Avatar
Senior Member with 244 posts.
 
Join Date: Jul 2005
Experience: Intermediate
19-Jun-2007, 05:51 AM #9
I can't seem to be able to post in your other thread over at the security forum...
BUT
have you tried formatting and reinstalling? After all, if your pc is infected, you will probably not be doing yourself any favours by simply uploading a backup.

is your webserver hosted on your own machine? or another hosting company? if the latter, you could contact them and let them know of the problem. They might be in a better position to sort it out.

if it's on your own machine - format reinstall and setup everything again. Maybe the hackers don't like the fact that you're using "l33t" as part of your company's name????
Sequal7's Avatar
Computer Specs
Distinguished Member with 2,369 posts.
 
Join Date: Apr 2001
Location: Around the corner!
Experience: Including today?
19-Jun-2007, 01:06 PM #10
If you are restoring to an earlier version of your database, IE; before the hack, then you should be ok temporarily.

You obviously need to tighten your installation by at least moderating posts or moderate users to stop the "hackers" (although they are not hacking your server, they are simply exploiting a security flaw in your software)
And as futile as it seems, ban their IP and username or email address (and keep banning the oclets they use) or they will continue to damage your site.

There is no need to format your computer and I see that your forums are hosted by a webserver, so you shouldnt worry much, they would let you know if your site was causing damage to their server promptly by banning or suspending your site.


In as far as your security post, allow the process to connect, it is required as part of the Windowz XP OS and zonealarm should allow the connection. BTW, no one can post in that thread (except the members who are certified) so you can bump all you want to and you may not get an answer for quite some time,
__________________
Good Luck on your fix

My real hobby..JoyCo
My real Job..(Second Hobby) IAFF Local 1865
Like the sites? My hobby is the one that created them!
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 12:47 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.