Quote:
Originally Posted by Jester1423
Ok guys I need serious help. We were hacked and I was able to delete the Admin accounts the hackers added. Looking at the CP log all they changed was the Notice.php But I have no idea were to go to clean up the mess they made. Any help would be great.
www.jeepasylum.com
--------------- Added [DATE]1378993172[/DATE] at [TIME]1378993172[/TIME] ---------------
I figured it out and feel slightly stupid now. Any suggestions on how they might have been able to add admin accounts and how I can prevent this in the future.
|
STEP 1: Login to ADMINCP
STEP 2: In the left-hand margin, scroll down to NOTICES
STEP 3: Click on NOTICES
STEP 4: DELETE the notice with the hacker message
STEP 5: Find the new admin account(s) they created.
STEP 6: Note the IP address(es) used to create the admin account(s)
STEP 7: DELETE the admin account(s) they created.
STEP 8: BAN the IP address(es) they used.