Log in

View Full Version : My forum is under Hacking attack


sdfaheem
03-27-2008, 08:29 AM
Since morning today somebody is trying to hack my forum.
They are frequently modifying or deleting code from many php files.
My host has restored the forum twice but they are continuosly hacking the files.
please somebody help me at the earliest.

I chmod all the files to 644 and changed the names of admincp and modcp directories too.
I don't understand how to stop this ongoing attack.:confused:

Kalina
03-27-2008, 08:40 AM
Did you try changing your ftp/web panel password?

sdfaheem
03-27-2008, 08:42 AM
Did you try changing your ftp/web panel password?

Yeah, i changed the passwords of my ftp as well as host control panel

Kalina
03-27-2008, 08:49 AM
I hope your host is looking into securing the server or making sure it's secure, also, you should look at your raw access logs to see how and what they're doing.

sdfaheem
03-27-2008, 09:07 AM
my host has restored the db thrice by now, changed all the master passwords.
i looked at raw access logs but didn't find anything suspicious, may be i couldn't locate it as its new for me

Dismounted
03-27-2008, 09:19 AM
Are you only running vBulletin?

Kalina
03-27-2008, 09:25 AM
And what plugins, if any, do you have installed?

Marco van Herwaarden
03-27-2008, 10:14 AM
Is this a dedicated or a shared server?

90% chance that they are hacking you on the server level. Restoring your own files and database will not close such a vulnerability and probably only your host can do so. I would put a bit of pressure on your host and ensure that they close any vulnerabilities before even trying to restore anything.

sdfaheem
03-27-2008, 05:15 PM
Is this a dedicated or a shared server?

90% chance that they are hacking you on the server level. Restoring your own files and database will not close such a vulnerability and probably only your host can do so. I would put a bit of pressure on your host and ensure that they close any vulnerabilities before even trying to restore anything.

Its a reseller account Marco.
And now i see that all the sites which are hosted on this host are down, i mean other client's sites, may be the server is under attack or might be they shut it off to prevent further hacking attempts. Don't know whats going on but i am really pissed off.

BTW, What do you think of Yahoo small business hosting? They provide unlimited bandwidth usage, and my forum averages 30 GB of bandwidth per month. I now feel that i should try out another host?
Please suggest me a reliable and affordable (cheap) host.

Regards

Marco van Herwaarden
03-27-2008, 06:02 PM
If all sites on that host are down, then it only confirms my guess that your site was hacked on a server level. Sounds like a host who has no (good) control over their security.

Try another host? I would not be very confident to stay with the same host after such thing happened, but also depending on how they react to a situation like this, how long it will take them to get things sorted, if they can give some degree of garantee that vulnerabilities have been closed, etc...

I can not suggest any specific host, but there is no such thing as "unlimited", for me a claim like that put up red flags.

mystic10
03-27-2008, 09:49 PM
try this one if it fits u..very affordable and they have 24 hours online support...maybe u want to check it out...www.computinghost.com