Today I was hacked using an offsite admin.php hack. I'm running phpnuke 7.4 with no security patches etc. Yes I know it's my fault I haven't been updating and as of now i've shutdown my site. I'm supplying information on the hacker, the method and the reasons I was hacked to you for your information.
Woke up today to find my server sending masses of spam, mostly to mtv.com.br and yahoo.com.br addresses. Immediately killed sendmail and cleared the entire queue (29,000 emails deferred).
So he had dumped some kind of proxy on my box as well as a apache replacement. Killed the processes, and of course the files used are gone. Looked through the nuke db and doesn't seem like any users were created at all, just seemed to use this exploit to dump the files and run them on my nix box.
Not sure i'll bring up my site again after this, i'll read through the various threads and security docs here and decide what to do.
Evaders99 Site Admin
Joined: Aug 17, 2003
Posts: 12403
Posted:
Wed Jun 22, 2005 8:06 am
Looks like what they were doing was through the Forums itself. phpBB versions less than 2.0.15 are vulnerable.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum