NukeXchange Network

          

NukeZone Hosting - Fast, Affordable and Dependable
Nuke Fixes · NukeForums · NukeZone Hosting · NukeUnited · Nuke Sites · Nuke Skins · NukeLance
Nuke Resources
 :: Home  :: Downloads  :: Your Account  :: Forums  :: Advertise :: 
Login or Register
Main Menu
General
 Main
 AvantGo
 Banner_Clients
 cfaq
 Donations
 Downloads
 Forums
 Members_List
 Private_Messages
 Search
 Stories_Archive
 Submit_News
 Surveys
 Topics
 Web_Links
 Your_Account

Your Account
 Login
 Register
 Lost Pass

Modules
Quick Links
· CMS Focus
· Domain Names
. Game Quest
· Learning Linux
. MateMaker
· NukeFixes
· NukeForums
· NukeLance
· Nuke Sites
· Nuke Skins
· NukeZone Hosting
. SearchDevil
Other Options

Download Resources
· Nuke Downloads
· Add a Link
· New Files
· Top Rated
· Most Popular

Web Site Resources
· Nuke Sites
· Add A Site
· New Sites
· Top Rated
· Most Popular

Support
· NukeZone Hosting
· NukeSkins.com
· NukeForums.com
· phpnuke.org
· NukeFixes.com
Information
NukeForums
·right blocks appear only to admins
·Special characters
·Header not working....
·No banner - Sunset-Theme (but $banner exists)
·Banners not showing on Sunset
·Installation Issues
·Looking for content warning/age verification system.
·Babebox Module Block Image Script
·Upload-Download
·Download Module error

read more...
Top10 Links
· 1: Nuke Forums
· 2: PHPNukeFiles
· 3: NukeSkins
· 4: Nuke Templates
· 5: EcomJunk
· 6: MDesign
· 7: Windows Installation: PHP
· 8: FLASH-FOR-NUKE
· 9: Dezina
· 10: Global Dream News Sharing Portal!
Site Visitors
User Login:

Nickname:
Password:
Security Code: Security Code
Type Security Code Here:

Members List Membership:
Latest: Blizz
Today: 0
Yesterday: 1
Overall: 15008

Visitation:
Guests: 695
Members: 0
Total: 695


You are Anonymous user. You can register for free by clicking here
Sponsor Links
Download the Best Archiver in the World
Download the Best Archiver in the World

NukeResources :: View topic - Hacked then Patched and still vulnerable...
NukeResources Forum Index

NukeResources Forum Index -> Upgrading PHP-Nuke -> Hacked then Patched and still vulnerable...
Post new topic  Reply to topic    View previous topic :: View next topic 
Hacked then Patched and still vulnerable...
PostPosted: Thu Aug 03, 2006 12:56 am Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




OK...here'r my story....

My site was recently hacked running 7.8 not patched. I went through the log file and found out where they hacked me from...it's a site with a hack webpage that you put the admin name in (don't even need a PW) and then tell it to create a new admin and voila...it creates a new admin that gives you access to everything!!

I took a back up that I had from the 29th and threw it up on a test site and applied the new 3.2 patches for 7.8 with bbtonuke 2.0.21NP. I go to the site where the hacker got me from and ran their little script and it's still creating an admin account!

Short of installing Sentinel (if that will even work) what can be done?? I will not post the site and the hack here so if you would like to see it, please let me know and I will PM it to you...admins only!!!

Please help me out on this if you can...Evaders...I'm sure you have an answer for me!!!!! If you need more information, please let me know!!!

Thanks!


Last edited by TRUFR34K on Thu Aug 03, 2006 2:34 am; edited 3 times in total
View user's profile Send private message
PostPosted: Thu Aug 03, 2006 1:02 am Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




And another question...how do you find out if you are using the patched files...other than knowing you uploaded them???
View user's profile Send private message
PostPosted: Thu Aug 03, 2006 1:02 am Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




Double post sorry! Delete if necessary!!
View user's profile Send private message
PostPosted: Thu Aug 03, 2006 10:45 am Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




OK...I have changed my admin.php file to a different name and that seems to give the hack site a 404 error...but whenever I try to do certain things inside the admin panel, it gives me an access denied! Any suggestions on that as well as I think changing that file will help prevent this??

The site that is running the hack, has a title of php-nuke-sql injection if that helps at all!!!!
View user's profile Send private message
PostPosted: Thu Aug 03, 2006 5:12 pm Reply with quote
Evaders99
Resource Master
Resource Master
 
Joined: May 25, 2004
Posts: 1785




Well if your mainfile.php has the Patched copyright code, you should be running it. Make sure you have uploaded all the files.

As I told him, by itself, that script can't do anything. It needs to figure out your admin login hash... which is usually done by stealing your admin cookie. Somewhere, the hacker has used code to grab that data, usually by inserting javascript code on your site. When you hit it, it sends back to the hackers site and gives them the correct hash. You need to change your admin password ASAP. Also, it does require knowledge of the admin script name, which you changed.. that's a good thing.

- Did you change your admin file in the config.php ? Are you running older scripts that don't support 7.6 and higher?

You may need to secure your site with Sentinel too. Also, any other insecure modules you are running? vWar and coppermine seem to be active targets. Also anything that allows uploading?
Check your site for any backdoor files your hacker has left behind

_________________
- Star Wars Rebellion Network - Evaders Squadron Coding -

Need help? Nuke Patched Core, Coding Services, Webmaster Services
View user's profile Send private message Visit poster's website AIM Address
PostPosted: Thu Aug 03, 2006 6:01 pm Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




Yeah my mainfile says it's the patched version!

I did change my admin.php filename as well as reflected it in my config.php but over 95% of my admin functions are not working. They give me the access denied...any suggestions on that?

You know...I do have an attachment mod loaded on my website...do you think they could have used that to insert javascript? And I am unsure if that is safe for 7.8 or not...it doesn't really say anything about what version it's for! But my question is, the person that did this hacking...the first time he entered my site, he did nothing other than go to the search function...which I thought he was doing to find out an admin user name. The next time he connected to my site was through the link that I gave you. Why wouldn't I see him connecting to try and insert some javascript to gain my PW through my cookies?

Also, is the reason that I can automatically create a new admin account because my admin info is in my cookie??

And last question...for now...if I just insert my backed up sql file and recreate my db, can I just upload 7.6, run the de-stall script and be running 7.6? Is that possible? I just don't want to lose any of my users or forum information.

As soon as I am done with upgrading/downgrading, I will be installing sentinel!!!

Again...thanks for your help Evaders!!!
View user's profile Send private message
PostPosted: Fri Aug 04, 2006 2:44 am Reply with quote
djdiper
Resource Seeker
Resource Seeker
 
Joined: Apr 07, 2006
Posts: 16




Run the downgrade script when you have 7.8 tabels installed in your database.

Then overwrite all files with the new 7.6 files.

Then the downgrade is complete.
View user's profile Send private message
PostPosted: Fri Aug 04, 2006 11:24 pm Reply with quote
TRUFR34K
Resource Newbie
Resource Newbie
 
Joined: Dec 15, 2005
Posts: 28




OK Evaders I have destalled to 7.6 and patched it up to 3.2b...and it's great!!! EXCEPT for ...it's adding the slashes when I edit things in the admin panel. I have exhaustively searched and found some things but nothing that works for me!! Can you point me in the right direction on this?? I know that you have to have an answer for this!!

Thanks man!
View user's profile Send private message
Hacked then Patched and still vulnerable...
 NukeResources Forum Index -> Upgrading PHP-Nuke
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT - 4 Hours  
Page 1 of 1  

  
  
 Post new topic  Reply to topic     



Powered by phpBB © 2001-2005 phpBB Group.     Theme created by Vjacheslav Trushkin.
There have been 248 unique hit(s) in the past 24 hours.
Forums ©
NukeZone Hosting - Fast, Affordable and Dependable


Best viewed with a Browser
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2001 - 2007 by NukeResources.com
You can syndicate our news using the file .backend.php or ultramode.txt
PHP-Nuke Copyright © 2004 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.25 Seconds

:: Eos phpbb2 style by Cyberalien :: PHP-Nuke theme by www.nukemods.com ::