View Full Version : HELP, URGENT HELP!!!!!!
Tezna
05-07-2009, 05:52 PM
MY SITE IS DEAD, please, what happend?
http://komouipets.comuv.com/adoptables/index.php
Seapyramid
05-07-2009, 05:59 PM
Looks like a hack.. try uploading all files via FTP overwriting your current files.
eaglelegend
05-07-2009, 06:29 PM
was it working fully beforehand?
Tezna
05-07-2009, 06:47 PM
yez, it was!
eaglelegend
05-07-2009, 07:01 PM
what can I say... youve been hacked, now have you got a backup of your work?
mugwumpr
05-07-2009, 10:00 PM
Does this imply a security hole in the host or the script?
Seapyramid
05-07-2009, 10:07 PM
Mystic Grove was hacked today.. but I believe that hole to be in Joomla... not this script. However, this particular hack is common ATM. It is a simple redirect hack that does not "infect" personal systems, just annoys them. It infects the index pages & adds an image.php file to image folders. The best way to protect against it is to CHOMD all index files to 444.
Sea
mugwumpr
05-07-2009, 10:16 PM
Do you know if it's specific to Joomla 1.0 or 1.5, or both?
Seapyramid
05-07-2009, 11:16 PM
Well I had thought it was specific to 1.5.. but now seeing a non Joomla site hit the same way I don't believe it specific to Joolma
BMR777
05-08-2009, 01:30 PM
Well, looking at the errors your site is showing it seems that it is having trouble loading the links from the database as well as (possibly) the template file.
As far as this being a script exploit, the only place an exploit file could have been uploaded is from the Admin CP (which requires admin access) and even if they could get a .php file uploaded to the picuploads/gif or picuploads/jpg folder it would almost certainly not execute as the .htaccess file in the gif and jpg folders turns off PHP for that directory (if your server supports this) and also forbids file access to files with .php extensions so anyone attempting to access them would get a 403 forbidden error.
Do you have any more details as to what happened?
Did you ever post your username / password in the public forums when seeking support and never remove or change them?
Tezna
05-08-2009, 04:22 PM
no, I just knowticed my mysql databases were deleted :(
BMR777
05-08-2009, 04:23 PM
Ok, that is odd. Did your host do any maintenance recently where they may have deleted the databases? What other scripts, if any, are you running on your site?
Tezna
05-08-2009, 09:49 PM
none, I haven't looked at then databases sciense I made them ;O
Seapyramid
05-08-2009, 10:46 PM
Look at this http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/
I have found this to be MG's issues & I am working on it now. This is NOT a php adoptables script issue! It affects ANY php site!
vBulletin® v3.8.11, Copyright ©2000-2025, vBulletin Solutions Inc.