Navigator Internet Solutions, Inc | Community  

Go Back   Navigator Internet Solutions, Inc | Community > Interactive Forums > Support & Questions
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Welcome to the Navigator Internet Solutions, Inc | Community forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Support & Questions Do you want to make public your Support Question? Feel free to post and you will receive a reply You don't need to be registered to post/reply here.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-23-2005, 01:47 PM
Bryan G's Avatar
Bryan G Bryan G is offline
Junior Member
 
Join Date: Jan 2005
Location: West Oahu, Hawaii
Posts: 27
Send a message via ICQ to Bryan G Send a message via AIM to Bryan G Send a message via MSN to Bryan G Send a message via Yahoo to Bryan G
Default Someone hacked into my site

On my domain http://michiganliving.com someone hacked into it and changed the page, I was running phbb and now they have some kind of JavaScript forwarding to another page.
Is there a way I can recover without having to loose all the posts that were in the forum?
Reply With Quote
  #2 (permalink)  
Old 11-23-2005, 02:14 PM
Bryan G's Avatar
Bryan G Bryan G is offline
Junior Member
 
Join Date: Jan 2005
Location: West Oahu, Hawaii
Posts: 27
Send a message via ICQ to Bryan G Send a message via AIM to Bryan G Send a message via MSN to Bryan G Send a message via Yahoo to Bryan G
Default

I turned off javascript and now I can log into the admin section, I found where they added some script, they added javascript to where you place "site description" and changed the script path, but it's still hacked, and I can't find any other things that look wrong....
Reply With Quote
  #3 (permalink)  
Old 11-23-2005, 02:52 PM
Bryan G's Avatar
Bryan G Bryan G is offline
Junior Member
 
Join Date: Jan 2005
Location: West Oahu, Hawaii
Posts: 27
Send a message via ICQ to Bryan G Send a message via AIM to Bryan G Send a message via MSN to Bryan G Send a message via Yahoo to Bryan G
Default

ok, the last place they had the javascript was where you name the category.
They either hacked my username/password or they know the layout of phbb and they just called up the page they wanted like http://michiganliving.com/admin/file.???
Is there a way to stop them from going any deeper than the root dir?
Reply With Quote
  #4 (permalink)  
Old 11-23-2005, 06:37 PM
NIS-Francisco's Avatar
NIS-Francisco NIS-Francisco is offline
Administrator
 
Join Date: Dec 2003
Posts: 528
Send a message via ICQ to NIS-Francisco Send a message via AIM to NIS-Francisco Send a message via MSN to NIS-Francisco Send a message via Yahoo to NIS-Francisco
Default

Quote:
Originally Posted by Bryan G
ok, the last place they had the javascript was where you name the category.
They either hacked my username/password or they know the layout of phbb and they just called up the page they wanted like http://michiganliving.com/admin/file.???
Is there a way to stop them from going any deeper than the root dir?
Hello,

PHPbb is one of the most insecure Forum software we have seen, since the worm that was surrounding the internet last time (around 8 months ago or so).

Best option you have is migrate to www.SimpleMachines.org which is better, faster and secure.

If you want to keep running phpBB at your own risk, load a backup from last week and restore it. After you do that UPDATE the phpbb software to the latest version on www.phpbb.com

Let me know if you have any questions
__________________
Best Regards,
Francisco Mazzeo
Navigator Internet Solutions, Inc
Resource-Shack
Reply With Quote
  #5 (permalink)  
Old 11-23-2005, 07:14 PM
Bryan G's Avatar
Bryan G Bryan G is offline
Junior Member
 
Join Date: Jan 2005
Location: West Oahu, Hawaii
Posts: 27
Send a message via ICQ to Bryan G Send a message via AIM to Bryan G Send a message via MSN to Bryan G Send a message via Yahoo to Bryan G
Default

Quote:
Originally Posted by NIS-Francisco
Hello,

PHPbb is one of the most insecure Forum software we have seen, since the worm that was surrounding the internet last time (around 8 months ago or so).

Best option you have is migrate to www.SimpleMachines.org which is better, faster and secure.

If you want to keep running phpBB at your own risk, load a backup from last week and restore it. After you do that UPDATE the phpbb software to the latest version on www.phpbb.com

Let me know if you have any questions
I already got everything up and running again, it's not a big hack, they just added some JavaScript in a few spots and I was able to take it out.

I'm running SimpleMachines on my other sites, I just didn't want to switch this one because I didn't want loose what was in the database, even though it's not much. Now after this I'm probably going to switch anyway. None of this is a big deal, it's more or less a dead forum, only one user ever posts, but it's an easy way to keep the domain active, and it's a good one. I do plan on getting the site going again when I move back to Michigan.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 10:05 AM.


Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0 RC6
Copyright © 2003-2005 Navigator Internet Solutions, Inc (NIS - NavigatorIS). All Rights Reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106