![]() |
Quote:
Quote:
Quote:
You're lashing out at everyone and everything here, making wild accusations, yet obviously having only very limited knowledge of what you're talking about. It's sad that you have been hacked numerous times, but it will not help you at all if you're pointing at a perfectly normal file with perfectly normal contents. You really need to understand this: If someone is able to read the contents of your config.php, you already have been hacked. It's too late. Step back, calm down, breath through. There's people here trying to help you, and you're lashing out at them in a way that is really not called for. |
True, renaming config.php stopped the site.
Then, my provider is telling me what is either not true or I don't understand You have changed password for ftp mysql Sorry if I have left that taste of lashing on everyone, my apologies. |
Its ok loua you're frustrated, we understand and we really just want you to understand so its easier on you despite some of our comments always take them with a grain of salt my friend :D.
- Think of it this way, yes you're right its stored right there in the file but how can they get to it using my example above? If anyone could simply download that file hackers would be taking down sites by the second, most software vBulletin, IPB, even free phpBB forums, Wordpress, the lot of them all use some form of configuration file where the details are stored. Regarding your issue: Yes, if you went into cpanel and changed the database users password, then nothing "automatically" changed it everywhere else for you :( so with that being said hurry and edit config.php with the new password and it should come right back up :). Also you cannot simply rename config.php to another name unless you make other file edits, best to leave it as-is unless testing as Cell mentioned above. One other thing to mention is, whomever setup the forum initially had to manually rename config.php.new to config.php, then edit the file and enter in your database name, username, and password to the database so that is why most of us were shocked by your statements - we just couldn't figure out why this was just now surprising you... I see where you were coming from, sure its thinkable but glad we steered you in the right direction! |
Without knowing what exactly you asked your provider, what you did in cpanel, and what exactly their answer was we really can't comment properly. No offense, but from the course of this thread I tend to believe that there may be some misunderstandings on your part.
It really seems your site (including the database, not only the files!) was never properly scanned for hidden backdoors etc. after the first attack. As others have speculated, I would assume that all those attacks may be follow-ups. Whatever your password, however secure, if there's some sort of backdoor present, it won't help you (since they don't have to get in, they are already in - all the time). But all of this has nothing to do with config.php, really. |
the only one time i got hacked was because i used a malicious ftp client
use only filezilla downloaded from their official site could also be a password stealer or other types of malware on your computer do you use cracked apps or games downloaded from p2p sites? obviously you'll answer you don't but for the record they're almost always infected with malware |
Quote:
Also cracked programs have nothing to do with what the OP is talking about. I'm not really sure where you are going here. |
Quote:
Quote:
|
Quote:
--------------- Added [DATE]1441914930[/DATE] at [TIME]1441914930[/TIME] --------------- Quote:
|
Quote:
why do you think htaccess encrypts passwords? just for teh phun? not using encrypted passwords means that if the ftp is compromised then the database is automatically compromised as well, it wouldn't be the case with encrypted password, think before you type something really stupid the only reason i can see for vbulletin to not use encrypted passwords is for customer convenience, but convenience is often the worst enemy of security |
Do you know about security?
htaccess doesnt encrypt passwords, its just a file with some rules in it. It can use them using htpasswd. Quote:
Even if you would encrypt the content, it has to be decrypted to make use of it. So can the hacker, since he can find the algorithm used in the files. And as said here, most, if not all scripts (Forum, Chat, CMS, Blog etc.) that use a database store their config data plain text in files, so its not "vB only" problem. |
All times are GMT. The time now is 09:40 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|