Sub Menu
Links Menu
Online Users

In total there are 302 users online :: 4 registered, 0 hidden and 298 guests

Most users ever online was 1091 on Wed Aug 16, 2023 5:27 pm

Registered users: Bing [Bot], Google [Bot], Helter, Majestic-12 [Bot] based on users active over the past 60 minutes

Code injected into forum

Support for IntegraMOD 141

Moderator: Integra Moderator

Re: Code injected into forum

PostAuthor: .QUACK.Major.Pain » Sun Nov 22, 2009 2:28 pm

Fixed the first one you posted.

The second is nothing related.

Code: Select all
//// Link categories dropdown list//foreach($link_categories as $cat_id => $cat_title){         $link_cat_option .= "<option>$cat_title</option>";}        


Line 691 is the foreach line.
Looks like a coding issue.

I contacted my host and this was their reply]Hello Breck,

Thank you for contacting us.

It appears that your site was hacked by someone who was able to log in using your FTP credentials. We are not 100% as to how they were able to obtain your login credentials, however we do believe it was due to an exploit called Gumblar, which uses a vulnerability in Adobe software products like Acrobat Reader or Flash Player to capture your FTP information and send it out on the internet.

You will need to change your FTP password, otherwise your account can still easily be compromised. Your FTP password is actually the same as your cPanel password. To update your FTP password:
1. Log into your cPanel
2. Click the, "Change Password" icon
3. Type in your new password, and click, "Change your password now!"

We strongly suggest that you update your Adobe products with the latest security patches available. A link to Adobe's security center can be found in our following Knowledge Base article, entitled, "Website Security":
[/quote]

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: Code injected into forum

PostAuthor: .QUACK.Major.Pain » Sun Nov 22, 2009 2:31 pm

Quick question, how did you, or how do you search an entire sites file system for such a thing?
Without viewing every file individually?
I want to check my other sites for any traces.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: Code injected into forum

PostAuthor: Helter » Sun Nov 22, 2009 2:36 pm

you have renamed your backup folder?
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4167
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 172.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: Code injected into forum

PostAuthor: .QUACK.Major.Pain » Sun Nov 22, 2009 2:40 pm

Yea - but I think I will change it again to be safe.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: Code injected into forum

PostAuthor: CaNNon » Sun Nov 22, 2009 2:54 pm

Quick question, how did you, or how do you search an entire sites file system for such a thing?
Without viewing every file individually?


firebug <img>
Image
Image
User avatar
CaNNon
Sr Integra Member
Sr Integra Member
 
Posts: 750
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 19, 2007 11:15 am
Cash on hand: 0.00

Re: Code injected into forum

PostAuthor: .QUACK.Major.Pain » Sun Nov 22, 2009 3:21 pm

How would I do it?
Select script?

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: Code injected into forum

PostAuthor: CaNNon » Sun Nov 22, 2009 5:03 pm

I used net and console (with full error settings). I never thought to try script but it may work too. <img>

Best thing is just play with it a bit and things just start to click for you.
Image
Image
User avatar
CaNNon
Sr Integra Member
Sr Integra Member
 
Posts: 750
Likes: 0 post
Liked in: 0 post
Joined: Thu Apr 19, 2007 11:15 am
Cash on hand: 0.00

Previous

Return to IntegraMOD 141

Who is online

Registered users: Bing [Bot], Google [Bot], Helter, Majestic-12 [Bot]