Article Dashboard Compromised Problem

Discussion in 'Security' started by iloveRP.com, Jun 20, 2010.

  1. #1
    we have an article dashboard article directory and it is often hacked. we always end up deleting or overwriting the compromised files. we set the permission to 755 to all files, yet we are still hacked.

    what's the best way to secure article dashboard?
     
    iloveRP.com, Jun 20, 2010 IP
  2. madaboutlinux

    madaboutlinux Member

    Messages:
    250
    Likes Received:
    7
    Best Answers:
    2
    Trophy Points:
    43
    #2
    What exactly the hack means? Are they injecting any contents in your files OR completely overwrite your files? Are you the owner of the server your website is hosted on? If no, it's more likely the server is hacked and hacking websites hosted on it all the time. Have your hosting provider to check the server in such a case. If you own the server, have a server management company to look into it OR hire an admin.
     
    madaboutlinux, Jun 21, 2010 IP
  3. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Could be a number of reasons. A fault in the software running on the website that allows remote code execution. It may be another site on the server that is hacked and can write to your account. Hackers may have left a backdoor script that allows them to edit your site as they wish. They may have your ftp password, they may have the admin passwords. Until you can work out how they are getting in then your really just guessing at a solution.

    Article Dashboard, but its encoded with ioncube, so you cant do anything about that, maybe try updating to the latest version and protecting the admin directory with an .htaccess file.
     
    phpSiteMinder, Jun 22, 2010 IP
  4. iloveRP.com

    iloveRP.com Peon

    Messages:
    457
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Thank you madaboutlinux and phpsiteminder. The site is sitting on a shared hosting. The last hacking incident involved the header file of the site being replaced with a meta refresh so that all traffic to my site was redirected to the hacker's url.

    Should I contact my host? What should I ask my host to do for my shared account?
     
    iloveRP.com, Jun 22, 2010 IP
  5. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Permissions 644 would be more secure. Which engine are you running?
     
    nikb, Jun 23, 2010 IP
  6. iloveRP.com

    iloveRP.com Peon

    Messages:
    457
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Sorry for asking, but what do you mean by engine?
     
    iloveRP.com, Jun 23, 2010 IP
  7. superfrankie

    superfrankie Well-Known Member

    Messages:
    1,166
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    180
    #7
    Article DB is a wonderful script but no updates regarding its upgrades or security fixes. Better setup .htaccess with authorized password
     
    superfrankie, Jun 23, 2010 IP
  8. iloveRP.com

    iloveRP.com Peon

    Messages:
    457
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #8
    do you have a sample code that i should put in my .htaccess?
     
    iloveRP.com, Jun 23, 2010 IP
  9. superfrankie

    superfrankie Well-Known Member

    Messages:
    1,166
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    180
    #9
    superfrankie, Jun 24, 2010 IP
  10. iloveRP.com

    iloveRP.com Peon

    Messages:
    457
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Thanks frankie. I was also advised by my host to password-protect certain directories of the site.
     
    iloveRP.com, Jun 24, 2010 IP
  11. superfrankie

    superfrankie Well-Known Member

    Messages:
    1,166
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    180
    #11

    Good Luck Friend
     
    superfrankie, Jun 24, 2010 IP
  12. nikb

    nikb Peon

    Messages:
    93
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #12
    I'm got answer to my question.
    If you are not using simple default passwords, i'm can say that this is a shared hosting problem.
    Change permissions to 644. I'm do not see any other solution to fix it.
    .htaccess can protect your directories from outside, but not from inside.
     
    nikb, Jun 27, 2010 IP
  13. iloveRP.com

    iloveRP.com Peon

    Messages:
    457
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #13
    My host advised me to password protect certain directories using cpanel. Let's see how secure this is in the coming days.
     
    iloveRP.com, Jun 27, 2010 IP