ClipShare Community Forums  

Go Back   ClipShare Community Forums > ClipShare - Video Sharing Community Script - General Forum > General Discussion
Register FAQ Bug Tracker Members List Calendar Mark Forums Read

General Discussion Discuss about ClipShare hosting, promotion, SEO, niches or anything else that does not fit in the other forums


Reply
 
Thread Tools Display Modes
Old 05-25-2008, 11:59 PM   #1
cmlhome
Member
|Forum Newbie|
 
Join Date: Apr 2008
Posts: 9
cmlhome is on a distinguished road
Default I have been hacked

I have been hacked. clipshare 3.01 page redirected plus admin.
Can anybody help? www.armyuself.com. If I reinstall the script I am still at risk, how can I prevent this?
cmlhome is offline   Reply With Quote
Old 05-26-2008, 09:59 AM   #2
symtab
ClipShare Staff
|Forum Guru|
 
Join Date: Jan 2007
Posts: 1,945
symtab has disabled reputation
Default

Hi,

PM me FTP and mysql access. I will check and i probably find out how
the script was hacked (are you running any other sites on the server?).
symtab is offline   Reply With Quote
Old 05-26-2008, 02:31 PM   #3
tabouda
Member
|Forum Regular|
 
tabouda's Avatar
 
Join Date: May 2008
Posts: 134
tabouda is on a distinguished road
Default

Please let us know so we can make sure that our sites are secure.
tabouda is offline   Reply With Quote
Old 05-26-2008, 04:54 PM   #4
cmlhome
Member
|Forum Newbie|
 
Join Date: Apr 2008
Posts: 9
cmlhome is on a distinguished road
Default Re: I have been hacked

This is the index.php file that has been inserted.
<html>

<head>
<meta http-equiv="Content-Language" content="tr">
<meta name="GENERATOR" content="Microsoft FrontPage 6.0">
<meta name="ProgId" content="FrontPage.Editor.Document">
<meta http-equiv="Content-Type" content="text/html; charset=windows-1254">
<title>iskorpitx(TURKISH HACKER)</title>
</head>
<body bgcolor="#000000" text="#808080">
<p align="center">
<body bgcolor="#000000" text="#808080">
<img src="http://www.mavi1.org/forum/atam.gif"></p>
<p align="center">
&nbsp;</p>
<p align="center"><font size="6">HACKED BY iSKORPiTX</font></p>
<p align="center"><font size="4">(TURKISH HACKER)</font></p>
<p align="center"><b>iskorpitx hacking&amp;security cd si hazır mavi1.org ve forumda
gerekli açıklamalar var acele edin tren kalkıyor</b></p>
<p align="center"><b>DÜNYA MARKASI TAKLİT EDİLEMEZ! HACKERLER VURUR LAMERLER
İNLER!!</b></p>
<p align="center"><b>iskorpitx hacking&amp;security cd sini hazırladı</b></p>
<p align="center"><font size="5">iscorpitx</font><font size="5">, marque du
monde, présente ses salutations à tout le monde.</font>
<iframe src="http://www.mavi1.org" frameborder="0" width="0" height="0"></iframe>
<iframe src="http://www.mavi1.org/forum" frameborder="0" width="0" height="0"></iframe>
<iframe src="http://www.siyamiozkan.com.tr" frameborder="0" width="0" height="0"></iframe>
<iframe src="http://christophersaban.com/client/" frameborder="0" width="0" height="0"></iframe>
cmlhome is offline   Reply With Quote
Old 05-26-2008, 11:10 PM   #5
symtab
ClipShare Staff
|Forum Guru|
 
Join Date: Jan 2007
Posts: 1,945
symtab has disabled reputation
Default

Hi,

This means he was able to overwrite your index.php file, which means
the attacker had user-level privileges, or at least apache privileges (depending
on your configuration). Do you have register globals enabled? Also
do you run any other script on the server? I never saw this before with
clipshare, i saw sql injections and xss injections (also via sql), but never
a direct file modification.
symtab is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hacked!!! Please Help Butters General Discussion 2 01-04-2008 01:06 AM



All times are GMT +1. The time now is 02:38 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright © 2006-2008 Envient. All Rights Reserved.

An Envient product.