Quote:
Originally Posted by puertoblack2003
quick question, why would it be in phrase? wouldn't that be either in post or thread in db ?.Back when we had the forum that was being hacked by scripts kiddys because of a old mod here.And i was able to resolve it tru those two tables.
|
I never said it was "in" a phrase, i said search for a "phrase" that the hacker used, ie keywords.
--------------- Added [DATE]1224203268[/DATE] at [TIME]1224203268[/TIME] ---------------
Quote:
Originally Posted by Berethorn
I FOUND IT!
It was your base64 hint! There was base 64 code hidden in the templates table, in a row with the title "spacer_open" which was part of something I added long ago - I don't know what for. But I think it was a random placement of the base64 code. I copied and then deleted the offending code, and now the site seems to be back to normal! Absolutely stunning what some code in one obscure area can do...
So thank you so much everyone! and especially Quarterbore who came up with the key to the mystery in the end: is there any information you want from me to help with your tool? 
|
Keep your forum closed and update the forums, hacks, remove any files from the server that are no longer used, the security hole is most likely still there.