ad_network_ads.txt file hacked

Discussion in 'Co-op Advertising Network' started by jim, May 17, 2006.

  1. #1
    Recently my ad_network_ads.txt file on a phpbb forum was hacked. The webhost made the file unwritable which of course dropped all the coop ads.

    I'm curious to see if anyone has had this happen before and what was done to resolve the situation.

    Could all this have been prevented if I was more timely updating from 2.19 to 2.20?
     
    jim, May 17, 2006 IP
  2. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #2
    What do you mean the .txt file was "hacked" exactly? It sounds to me like phpBB was hacked, and then they edited the .txt file because of that.
     
    digitalpoint, May 17, 2006 IP
    jim likes this.
  3. jim

    jim Well-Known Member

    Messages:
    816
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    153
    #3
    You're probably right - All I know is that my control panel had 2 ad_network_ads.txt files and one of them said (hack removed). I can no longer chmod the .txt file (and it's no longer writable). I'm just wondering how unique my experience is and if anyone has faced it before, I could use some advice.
     
    jim, May 17, 2006 IP
  4. rocallag

    rocallag Peon

    Messages:
    51
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Interesting I was wondering if the .txt could be a problem. What was the contents? Are you saying someone just broke co-op by changing its permission or managed to execute something from it?

    Either way Shawn will want/need to know.

    Rob
     
    rocallag, May 18, 2006 IP
  5. jim

    jim Well-Known Member

    Messages:
    816
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    153
    #5
    My host still hasb't told me what they removed but if they had to intervene I guess they were able to execute something. It was 666, not 777 though...
     
    jim, May 18, 2006 IP
  6. rocallag

    rocallag Peon

    Messages:
    51
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Hi Jim,
    I think they put something in the file, changed its permissions to read only so its not overwritten. Each time a page is shown the .txt contents got executed via the 260 echo, they may have edited that file too - bit late for me to play and see. Its just a guess - looks like nothing wrong with co-op files - you were hacked beforehand and they used this as the delivery method.

    I wonder if theres a way to

    You log files may have some interesting tit-bits.

    Rob.
     
    rocallag, May 18, 2006 IP
    jim likes this.
  7. jim

    jim Well-Known Member

    Messages:
    816
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    153
    #7
    Well I'm in over my head here, so I hired someone to check things out. If he finds anything I'll report back.
     
    jim, May 18, 2006 IP
  8. dcristo

    dcristo Illustrious Member

    Messages:
    19,789
    Likes Received:
    1,201
    Best Answers:
    7
    Trophy Points:
    470
    Articles:
    5
    #8
    I'll betya it was phpBB which got hacked.
     
    dcristo, May 19, 2006 IP
  9. jim

    jim Well-Known Member

    Messages:
    816
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    153
    #9
    The guy I hired said that's possible but if phpbb were hacked the hackers would normally do a lot more than rewrite the ads.txt file. He also suggested that maybe the Admins from the web hosting company just screwed up and there never was any hack...
     
    jim, May 20, 2006 IP
  10. tech86

    tech86 Peon

    Messages:
    83
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #10
    PhpBB has had its share of vulnerability in the past few months, however what version of phpBB were you using. Would it be possible to upload http access logs?
     
    tech86, May 20, 2006 IP
    jim likes this.