Quote:
Originally Posted by romebaby
Email communicated with the hacker, as he was trying to get money from us. This is how he said he got in:
I exploited your site. Got that Admins HASH:SALT (which is the password encrypted). Once i gained acess i uploaded an AJAX code and upload a i47 shell. Then i looked at your config.php logged in to the SQL dump and dumped your database. Self killed the shell
I asked him to explain I exploited your site and he said "I ran a 4.2.x upgrade exploit."
|
I believe this exploit uses the upgrade.php file.
Are you sure you did not have the install directory in there at the time the site was hacked?
I would suggest you email all users and tell them to change log ins. in addition make sure you change all admin and server related log ins, database, ftp, etc.
Grab the admincp firewall and use it and be sure to protect your config using htaccess.
Lastly, many times these hackers lie to throw you off the trail. Check your server logs and see what went on yourself so you do not have to take his word for it.