Bad Thingy
Hey ,
I have Everything in the lastest version , and use cpanel .
And I've disable Shell , perl , c++ , gcc ..etc
And someone is using something ... and always delteting my database..
No matter what script or portal .. he's always doing it .
Is it a mysql exploit .. or what ?
I need help ( ASAP )
Busy posted this at 10:27 — 27th April 2005.
He has: 6,151 posts
Joined: May 2001
are you running phpbb, pukenuke or any of the other programs via cpanel?
if so are they updated to latest secure versions?
do your logs show anything?
do you run a cronjob?
Is it your own server or a hosts server? are there any .exe's or files in the root directory that shouldn;t be there (a worm or virus, trojan etc)
Assassin posted this at 22:53 — 27th April 2005.
He has: 77 posts
Joined: Apr 2005
If you have PHP enabled, there is a simple hack that can mess up all of your databases. I don't know the fix off the top of my head, but I'll get it to you if this is a possible problem. Let me know if it's possible.
Assassin Band Website
mairving posted this at 17:55 — 28th April 2005.
They have: 2,256 posts
Joined: Feb 2001
Really would need more info to give a good guess.
Is it a shared server? You are buying hosting from someone else. Then you should check with your host and let them look in their logfiles.
Is it a dedicated server? Is everything fully patched?
What OS are you running?
Are you using a CMS or other PHP/Perl script? Is it the latest version?
There is no hack that has anything to do with the current versions of PHP. There are certainly cross-scripting and sql injection vulnerabilities in scripts but these are readily identifiable and fixable.
Mark Irving
I have a mind like a steel trap; it is rusty and illegal in 47 states
Greg K posted this at 18:17 — 28th April 2005.
He has: 2,145 posts
Joined: Nov 2003
Wait a minute, is the same server that you have listed as "My server is secured !" (see http://www.webmaster-forums.net/showthread.php?t=29023 )
Also mentioned in another post, not sure if it is the same server "my site is phpnuke platinum !" (see http://www.webmaster-forums.net/showthread.php?t=29022 ) This information may help others help you find the problem.
If they are the same server, then I feel that you need to edit or delete your post advertising your server is secured until you can fix it.
-Greg
PS. Assisin, I use PHP, so send me the info on the fix to this hack that anyone can use to delete all my databases.
_sam_ posted this at 04:38 — 30th April 2005.
They have: 5 posts
Joined: Apr 2005
i have cpanel , and everything TO LATEST VERSION ,even the cpanel ...
I knew how he's hacking me , i have shell disbaled on all accounts , but still he's using mysql shell ! how can i stop that ?
andy206uk posted this at 17:14 — 30th April 2005.
He has: 1,758 posts
Joined: Jul 2002
Just because something is the latest version, doesn't mean that it's secure. It might be worth portscanning your server and seeing if you have any excess ports open and if you do get them locked down.
I'm not an expert on server security but I know for a fact locking down your server is the first step to security. Also, change all your passwords reguarlly to slow down their future atempts
Andy
mairving posted this at 22:15 — 30th April 2005.
They have: 2,256 posts
Joined: Feb 2001
Difficult to get help when people try to help you by asking questions and you don't answer.
Check your mysql database and see what is there. If there are any entries in there that use anything in the host field besides localhost, I would remove them or change the password. I would also change the root password as well. Might look at this as well.
Mark Irving
I have a mind like a steel trap; it is rusty and illegal in 47 states
Want to join the discussion? Create an account or log in if you already have one. Joining is fast, free and painless! We’ll even whisk you back here when you’ve finished.