ModMySite Support Forum  
Uptime verified by Wormly.com

Go Back   ModMySite Support Forum > aeWebWorks aeDating / BoonEx Dolphin Dating Script > Security / Server Administration

Security / Server Administration Security / server administration for aeWebWorks aeDating or BoonEx Dolphin Dating Script

Reply
 
LinkBack Thread Tools Display Modes
Old 12-23-2006   #1 (permalink)
 
Join Date: Jun 2006
Posts: 10
Default Front page hack - Turkish & Muslim hackers WAS HERE!!

I've just been hacked. When going to my URL, the hacker's page displays. HostforWeb fixed it by reloading all files, except the databases, from yesterdays backup.
Any suggestions on how to prevent this in the future?

Last edited by Boss; 12-23-2006 at 01:45 AM.
Boss is offline   Reply With Quote
Old 12-23-2006   #2 (permalink)
 
Join Date: Oct 2006
Posts: 25
Default

What Version is running on Your site.
Is Your register globals off ?
baris is offline   Reply With Quote
Old 12-23-2006   #3 (permalink)
 
Join Date: Oct 2006
Posts: 73
Default

Boss this is no good .. Can you please post more details ..

What Version you are running ...

What Mods you have install and any changes ..

Also you should get your server logs and send them to the admin here so they can see how they got in and then can shut the door ...

What you have just done to repair your site is a waste of time and YOU WILL be hacked again as you have not fixed where they got in ...

Also go through every folder and file and make sure they have not left anything behind (folder,File)... 9 out of 10 times they have and will be able to get back in using what they have left behind .. even if you have closed the hole they first used to get in .

2 in 2 days ..Posts made about being Hacked but with no details on how .. This is rubbish ..
smarty is offline   Reply With Quote
Old 12-23-2006   #4 (permalink)
 
Join Date: Jun 2006
Posts: 10
Default Turkish Hack

I haven't found the problem. I was hoping someone else was aware of this hack and knows how to stop it recurring.

I'm using Aedating 4.1. I've made some mods but nothing drastic that I think would be likely to open any holes.

I turned off Globals as soon as Smoge sent his message.

Both the homepage and the URL/admin page came up with the same screen.

I wasn't game to keep the page, but I printed it out and can scan it if someone can tell be how to upload a picture to this forum

Looks like I'm going to have a long night.

Last edited by Boss; 12-23-2006 at 06:28 AM.
Boss is offline   Reply With Quote
Old 12-23-2006   #5 (permalink)
 
Join Date: Oct 2006
Posts: 73
Default

Get hold of you server logs and ask Smoge to have a look at them .. that will show where they got in ..
smarty is offline   Reply With Quote
Old 12-23-2006   #6 (permalink)
 
Join Date: Jun 2006
Posts: 10
Default Turkish Hack -Sever logs.

I've sent to logs to admin as you suggested - and will look at them myself.
I didn't know they existed - thanks for your suggestion.
I will post anything I learn.
Boss is offline   Reply With Quote
Old 12-23-2006   #7 (permalink)
Administrator
 
Smoge's Avatar
 
Join Date: Mar 2005
Posts: 5,601
Send a message via Skype™ to Smoge
Default

Hi,

Quote:
Both the homepage and the URL/admin page came up with the same screen.
You need to fix the damage from the hack... turning off register_globals will not reset your site to "OK" - the damage/changes have already been done!

I am not sure why HostForWeb is setting up servers with register_globals on... but the last couple of modmysite users servers I worked on that were hosted there had register_globals enabled.

The hacks (as RR1024) will tell you - could be from other means - but register_globals being off is a great start.

Other simple steps are to .htaccess your admin directory - many people don't do that.

And run code that has been cleaned up some.... aedating and dolphin tend to be a little "susceptible". GPLdate - perhaps less so - or at least, we care about that aspect of the GPLdate code.

Another option you may want to try, is to consider hosting your site on FreeDatingHost.Com - our sister site... that server is configured a bit differently to help in the security area.. both for YOUR site, and for the OTHER sites on the server - since if they are hacked, if PHPSuExec is not being used - a hacker can use another account on a server to look at your files, including header.inc.php and so on. FreeDatingHost has PHPSuExec enabled (among other things).

On FreeDatingHost - we are considering disabling some functions that these hacks use - but are not used by aedating / dolphin / gpldate - to further twart them. We already disabled compiler access - since this is not needed - but often used by script kiddies.

Yes - the server logs can be very helpful.... but my guess is.. once you clean up the hack, and have register_globals off - you will be OK.

With the files cleaned up and register_globals off - are you 100% safe - no.... but I bet it stops.

Smoge
__________________
ModMySite Administrator

Problems? Questions? Need modifications or other help with your site?

Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.
Smoge is online now   Reply With Quote
Old 12-23-2006   #8 (permalink)
 
Join Date: Jun 2006
Posts: 10
Smile Thanks Smoge -

Thanks Smoge & Smarty - I will implement the fixes.
Boss is offline   Reply With Quote
Old 07-17-2007   #9 (permalink)
 
rr1024's Avatar
 
Join Date: Mar 2005
Posts: 147
Default

Here are some important HINTS to help secure your AED / Dolphin Site:

1. Change the Name of your Admin Panel Directory i.e. it's default is /admin/ to /adminMyDogsName/
Modify your header.inc.php to allow this.

2. Move All the files in the inc directory except header.inc.php to a directory outside your public html www directory

home/inc/*.inc.php all inc goes here except header.inc.php and js directory of course.
home/public_html/allAedUserFilesHere
home/public_html/inc/header.inc.php

Now if you really want to screw the stupid ass hackers...LOL do what I did....Create a bunch of FAKE php files and dump them into home/public_html/inc/ such has
design.inc.php with nothing in it
admin.design.inc.php with nothing in it....LOL

It provides hours of fun and laughs.....I even added some code so it would look like they made progress but still got nothing. and it would email me with each attempt and log IP/domain/agent..LMAO!!!!!

Remove all phpself's and just use the darn $site[url] . "filename.php"

Sanatize a simple example
PHP Code:
You must login or register to view the code on ModMySite.
Well hope that helps a little
__________________
Windows defined as 32 bit extensions and a graphical shell for a 16 bit patch to an 8 bit operating system originally coded for a 4 bit microprocessor, written by a 2 bit company that can't stand 1 bit of competition.
-----------------------------------------------------
My Aed site
Adult Sex Toys

My aed module test server for fun stuff
rr1024 is offline   Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Add members NickName to Blog page header and page text. Prometheus Free Mod Exchange 0 03-09-2007 06:50 PM
remove windows on front page chameleon General Troubleshooting 3 11-01-2006 08:21 PM
Change my front page welcome box harryapples Graphics / Templates 9 09-19-2006 08:11 AM
Gallery View on front page afrogeek Graphics / Templates 1 09-15-2006 12:17 AM
How do you add a gallery feature to the front page? afrogeek FAQ & HOWTO 0 09-06-2006 01:53 PM


All times are GMT -5. The time now is 10:27 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC7
Contents Copyright 2003 to the End Of Time - ModMySite.Com