Results 1 to 5 of 5

Thread: phpautomembersarea hacker buggers!!!

  1. #1
    virgin by request ;) Chilihost's Avatar
    Join Date
    Oct 2003
    Posts
    4,496

    phpautomembersarea hacker buggers!!!

    I had a client get his site hacked thru an insecure version of phpautomembersarea today, here's how they found it:

    http://www.google.com/search?q=inurl...=&start=0&sa=N

    if you are running this script, make sure its secured / updated!!!

    cheers,
    Luke


  2. #2
    Moderator Bec's Avatar
    Join Date
    Nov 2003
    Location
    Ohio
    Posts
    8,419
    I'd also like to add that if you have OLD VERSIONS databases like phpnuke on your domains that aren't being used - DELETE THEM!!!!! Don't leave up old copies of databases!!! It's a doorway to hackers and phishing of your sites. Remove the folders immediately and I'd also remove them from your control panel if they aren't being used by a current version.

    Also go see if you are running a current version of any scripts ... being even one version behind on an upgrade can prove to be a backdoor way into a domain.


  3. #3
    virgin by request ;) Chilihost's Avatar
    Join Date
    Oct 2003
    Posts
    4,496
    Yes, absolutely true Bec.....and because of this issue I lost my whole Saturday


  4. #4
    Moderator Bec's Avatar
    Join Date
    Nov 2003
    Location
    Ohio
    Posts
    8,419
    Luke brought up another good point. Once we figured out how they were finding sites to hack (easily via google looking for specific folders with hackable script names) ... a good rule of thumb is to NOT name a folder the same name as the script it contains!!!! GIVE IT A NEW NAME!! You may have to adjust your config file and possibly some links to reflect the new folder name, but that's a lot less painful than getting hacked.

    This whole experience also gives me pause about using "free" scripts that insist on having their script name/addy on every page unless you buy it ... again, opens up easily searched for domains using that script.


  5. #5
    Hot guys & hard cocks Squirt's Avatar
    Join Date
    Sep 2004
    Location
    USA
    Posts
    5,193
    Great tips guys thanks for the info :bunny:
    Naked Straight Men on Squirtit & StraightBro

    ~ In Production ~

    Blindfoldmen.com
    scifimen.com


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •