NukeXchange Network

          

Nuke Sites Link Directory
Nuke Fixes · NukeForums · NukeZone Hosting · NukeUnited · Nuke Sites · Nuke Skins · NukeLance
Nuke Resources
 :: Home  :: Downloads  :: Your Account  :: Forums  :: Advertise :: 
Login or Register
Main Menu
General
 Main
 AvantGo
 Banner_Clients
 cfaq
 Donations
 Downloads
 Forums
 Members_List
 Private_Messages
 Search
 Stories_Archive
 Submit_News
 Surveys
 Topics
 Web_Links
 Your_Account

Your Account
 Login
 Register
 Lost Pass

Modules
Quick Links
· CMS Focus
· Domain Names
. Game Quest
· Learning Linux
. MateMaker
· NukeFixes
· NukeForums
· NukeLance
· Nuke Sites
· Nuke Skins
· NukeZone Hosting
. SearchDevil
Other Options

Download Resources
· Nuke Downloads
· Add a Link
· New Files
· Top Rated
· Most Popular

Web Site Resources
· Nuke Sites
· Add A Site
· New Sites
· Top Rated
· Most Popular

Support
· NukeZone Hosting
· NukeSkins.com
· NukeForums.com
· phpnuke.org
· NukeFixes.com
Information
NukeForums
·decompressing EN-Book-Nuke.tar.tar
·How to allow spaces/gaps/"-" in allowed usernames
·How to Setup PHPNUKE on win2k
·cannot save changes
·voting?
·Nuke forum picture problem
·How to change smtp port on wampserver and windows
·yet another 301 redirect problem
·Image display? - newbie
·php nuke help

read more...
Top10 Links
· 1: Nuke Forums
· 2: PHPNukeFiles
· 3: NukeSkins
· 4: Nuke Templates
· 5: EcomJunk
· 6: MDesign
· 7: Windows Installation: PHP
· 8: FLASH-FOR-NUKE
· 9: Dezina
· 10: Global Dream News Sharing Portal!
Site Visitors
User Login:

Nickname:
Password:
Security Code: Security Code
Type Security Code Here:

Members List Membership:
Latest: qwertz
Today: 0
Yesterday: 1
Overall: 15102

Visitation:
Guests: 452
Members: 0
Total: 452


You are Anonymous user. You can register for free by clicking here
Sponsor Links
Nuke Sites Link Directory
Nuke Sites Link Directory

NukeResources :: View topic - site hacked!!!
NukeResources Forum Index

NukeResources Forum Index -> Bug Reports -> site hacked!!!
Post new topic  Reply to topic    View previous topic :: View next topic 
site hacked!!!
PostPosted: Sat Mar 13, 2004 1:46 pm Reply with quote
johnvamo
Resource Seeker
Resource Seeker
 
Joined: Sep 03, 2003
Posts: 14
Location: Venice




Hello,

Mi site have just been hacked....
Any on eknows how to get the admin password from the incrypted data from the database?

I can't logded in as admin...

Great....all fixes were implemented...so what was wrong?????

Thanks for eny help.-

www.latinoamericanos.org

Any one knows in what language the message is written?

Twisted Evil
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger
PostPosted: Sat Mar 13, 2004 11:06 pm Reply with quote
chatserv
Site Admin
Site Admin
 
Joined: Apr 21, 2002
Posts: 1732
Location: Puerto Rico




Change the password right at the authors database table just remember to select MD5 from the dropdown list next to where you enter the new pass, as for the site what fixes did you have and what third party add-ons do you have at the site? Several add-ons allow sites to be hacked with ease (i.e. MyeGallery)

_________________
NukeResources | ScriptHeaven
View user's profile Send private message Visit poster's website
hacked Site details
PostPosted: Sun Mar 14, 2004 7:03 am Reply with quote
johnvamo
Resource Seeker
Resource Seeker
 
Joined: Sep 03, 2003
Posts: 14
Location: Venice




Hello Chatserv, Thanks in advance for the help.

I use nuke 6.5 and I have applied, I think, all possibles bug fixes found four or five months ago...so ?

I have many addons: HTMLarea 3.1, Baribas Newsletter 1.70, IFRAME, Wherebisdu 1.5, MS Analysis 2.0, Nukewrap 1.0, Coopermine 1.1 beta 2,
NSN My account for nuke 6.5

What can be?

The hacker left messges in th news seccion, polls and messages.
Can be the news module the hole?

Thanks for the cooperation.

John
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger
PostPosted: Sun Mar 14, 2004 12:35 pm Reply with quote
chatserv
Site Admin
Site Admin
 
Joined: Apr 21, 2002
Posts: 1732
Location: Puerto Rico




I see you are using some WYSIWYG add-ons, those alter the allowed html tags by almost allowing all tags which is a big mistake as people can insert malicious code through them.

_________________
NukeResources | ScriptHeaven
View user's profile Send private message Visit poster's website
PostPosted: Mon Mar 15, 2004 9:20 am Reply with quote
johnvamo
Resource Seeker
Resource Seeker
 
Joined: Sep 03, 2003
Posts: 14
Location: Venice




I see...

Question:

1.If the WYSIWYG modules are inactive, are they still a hacker accesss?

2.Can I protect my site having a WYSIWYG module to be use just to registered members and as admin I control the registration of new members (not admiting user-self registration) ?

Thanks

John
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger
PostPosted: Mon Mar 15, 2004 5:25 pm Reply with quote
chatserv
Site Admin
Site Admin
 
Joined: Apr 21, 2002
Posts: 1732
Location: Puerto Rico




Making the add-on for reg'd users only or disabling it not always stops attacks, in some cases you don't even need to have it on your site (MyeGallery), it only takes one site to have it to make all others on a shared server to be vulnerable.

_________________
NukeResources | ScriptHeaven
View user's profile Send private message Visit poster's website
site hacked!!!
 NukeResources Forum Index -> Bug Reports
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT - 4 Hours  
Page 1 of 1  

  
  
 Post new topic  Reply to topic     



Powered by phpBB © 2001-2005 phpBB Group.     Theme created by Vjacheslav Trushkin.
There have been 133 unique hit(s) in the past 24 hours.
Forums ©
Need to find your IP fast?


Best viewed with a Browser
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2001 - 2007 by NukeResources.com
You can syndicate our news using the file .backend.php or ultramode.txt
PHP-Nuke Copyright © 2004 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.27 Seconds

:: Eos phpbb2 style by Cyberalien :: PHP-Nuke theme by www.nukemods.com ::