My Forum(Smf script) is Hacked what next???

Discussion in 'Site & Server Administration' started by gsv13, Jan 17, 2008.

  1. #1
    Hi guys my mobile forum
    http://www.mobiletalk.in/ has been hacked ..... Don't know what to do next(also how to react :p)??? I am using same hosting account for many other sites ..... just this one has been hacked!!!
    Can any one tell where the hacking took place??? Also I was using SMF for the forum!!! What next ??? Anyone to help or for quick advice plz add me to msn or reply here asap!!!
     
    gsv13, Jan 17, 2008 IP
  2. gsv13

    gsv13 Well-Known Member

    Messages:
    2,773
    Likes Received:
    114
    Best Answers:
    0
    Trophy Points:
    130
    #2
    no one to answer?
     
    gsv13, Jan 17, 2008 IP
  3. nuke13

    nuke13 Banned

    Messages:
    180
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Most likely the forum was hacked by finding an exploit in the software you was using on your forum. You should make sure the you have kept up to date with all of the security patches.

    They probably didn’t get access to the other files on the server because it was just access to this single script that they got.

    Have you had a chat to your host to make sure it was not some security risk with the operating system or apache? Or are you also hosting the site on your own server?
     
    nuke13, Jan 19, 2008 IP
  4. oc-scott

    oc-scott Active Member

    Messages:
    420
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    68
    #4
    Have you checked whether its a root level hack or its just with only 1 account? (Added you to MSN, I could help you to track the hacker.)
     
    oc-scott, Jan 19, 2008 IP
  5. gsv13

    gsv13 Well-Known Member

    Messages:
    2,773
    Likes Received:
    114
    Best Answers:
    0
    Trophy Points:
    130
    #5
    actually he corrupted all other sites on my hosting account including wordpress blog ..... One thing that is killing me is ... from where did this happened??? Guys at smf forum said .... there aren't any leaks in latest version(my forum was updated) ..... so I am thinking they might have entered via my fantastico installed wordpress ... which was updated till ver 2.3.1 (fantastico latest)
     
    gsv13, Jan 19, 2008 IP
  6. oc-scott

    oc-scott Active Member

    Messages:
    420
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    68
    #6
    Do you have root access to the server? If the hacker attacked all the other accounts in the server, then its probably a root hack. You might need the help of a server administrator to take a look into your setup. If needed, I could analyze the server security for free.
     
    oc-scott, Jan 19, 2008 IP
  7. gsv13

    gsv13 Well-Known Member

    Messages:
    2,773
    Likes Received:
    114
    Best Answers:
    0
    Trophy Points:
    130
    #7
    I am having this on shared hosting accounts with byethost(uk based) ....... I don't think i have a root access ... Further more i think it is some one from there own employees ..... as the last guy to visit was someone from UK(statcounter stats show).
    So instead of messing it I decided to change host altogether to VPS. Still thanks for the help!!!
     
    gsv13, Jan 19, 2008 IP
  8. rllunzmann

    rllunzmann Active Member

    Messages:
    1,796
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    80
    #8
    I would contact the script originator and ask for any updates they have to the script. Also, what software is used in conjuction with this script? Such as, PHP, mySQL, etc... ?
     
    rllunzmann, Jan 21, 2008 IP