Forum Moderators: phranque

Message Too Old, No Replies

Turkish Hacker

My website defaced

         

Sierra_Dad

4:06 pm on Jul 17, 2006 (gmt 0)

10+ Year Member



I'm not sure how he exploited the site. Right now, I can't even find where ha has done the damage to put it back.

I've used Mambo 4.5.2.

What do I do?

physics

2:10 am on Jul 18, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Try posting at the mambo forums for one and also more details on what is broken. If your database is OK or backed up you might be able to start with the newest version of mambo and import the db.

Sierra_Dad

4:50 pm on Jul 19, 2006 (gmt 0)

10+ Year Member



I did find some help on Mambo forums.

I didn't know what was damaged, but apparently the configuration file was vulnerable and written to.

I did end up updating mambo. Of course, that caused a chain reaction where all the plugins, bridges, and components had to be resynchronized. It took a few days for the forum to work completely.

specter

9:48 pm on Jul 19, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Sticky me,if you want.

physics

6:55 am on Jul 20, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Glad to see you were able to fix it. Usually with any software like that you should remove the install dir after it's all set up and set the config file to be read-only.