You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 62 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Site Hacked - Defaced by D.O.M. [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Campo
Nuke Cadet
Nuke Cadet


Joined: May 22, 2005
Posts: 2


PostPosted: Wed Apr 05, 2006 4:21 am Reply with quoteBack to top

My site was recently hacked ( http://dof.nrgservers.net ). I was using the newest version of phpnuke (no sentinel). I have deleted and replaced all my main php files, yet it still shows this error. I also deleted the index.html files that were placed on my website. I have phpmyadmin and I checked my database. It looked the same as far as I know. Maybe I am missing something? I searched google for d.o.m. and it seems many other sites are hacked by the same method. I have read the posts regarding hackers and I plan to update my site with sentinel as soon as it gets fixed. Does anybody have any suggestions how to fix this before I totally wipe my database and directory and start from scratch? Thanks a lot.
Find all posts by CampoView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12403


PostPosted: Wed Apr 05, 2006 8:16 am Reply with quoteBack to top

They may have replaced some files. I would try loading a clean backup of your files

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
Coryf88
Nuke Cadet
Nuke Cadet


Joined: Jun 15, 2004
Posts: 2


PostPosted: Wed Apr 05, 2006 11:41 am Reply with quoteBack to top

Look in the nuke_config table. You will notice there is another row. Delete the one that has stuff about D.O.M.
Find all posts by Coryf88View user's profileSend private message
jt99
Nuke Cadet
Nuke Cadet


Joined: Apr 07, 2006
Posts: 4


PostPosted: Fri Apr 07, 2006 4:27 am Reply with quoteBack to top

This just recently happened to me, and I got caught with my pants down w/o a good backup.

I took a copy of my database how it was originally laid out w/ the site, and the pages w/ all mods installed and uploaded it to the server. I then took the hacked database and copied my forum posts, news posts, and users over to the new database by the old copy/paste method in a mysql dump.

All this, only to get hacked again a day later...

Running patched 7.6 and NSN 2.4.2
Find all posts by jt99View user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12403


PostPosted: Fri Apr 07, 2006 5:46 am Reply with quoteBack to top

Any idea how they got in? You'd need access logs for that
Then we can figure out if it is a security issue with the Patched files, Sentinel, or something else

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
ssace
Lieutenant
Lieutenant


Joined: Dec 29, 2005
Posts: 175


PostPosted: Sun Apr 09, 2006 6:14 pm Reply with quoteBack to top

My father has a nuke 7.8 but no patches or sentinel. He just got hacked. When you go to the site it just exposes all his files. Somebody calling themselves: Wildboy / Turkish Hacker

The emptyadmins.php script did not work. It just gave me the same hacked page.

Any ideas what to do now?
Find all posts by ssaceView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12403


PostPosted: Mon Apr 10, 2006 4:44 am Reply with quoteBack to top

You will need phpMyAdmin to go through your tables and remove their code

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
maxout
Corporal
Corporal


Joined: Aug 16, 2004
Posts: 64


PostPosted: Mon Apr 10, 2006 3:14 pm Reply with quoteBack to top

My site was hacked 3 times this week
by same bastard they leave this massage:

Quote:
HackeD By NetWorkeR

Lütfen Açıklarınızı Kapatınız || Please Fix Your Bugs !

T Ü R K İ Y E

Greetz : PowerCobra, Rawkmetal, Secretlyx, iskorpitx, TheHacker, ShadowBoys & All PowerHack.Org Users


Fatal error: Cannot instantiate non-existent class: sql_db in /home/grabiecr/public_html/db/db.php on line 86


How I can find theirs code in DB.. what I should looking for to delete?
Find all posts by maxoutView user's profileSend private message
ssace
Lieutenant
Lieutenant


Joined: Dec 29, 2005
Posts: 175


PostPosted: Mon Apr 10, 2006 5:56 pm Reply with quoteBack to top

I think mine is fixed. I didn't see anything wrong in the database...of course I don't know what to look for...hehe

My config.php file was all screwed up. I uploaded a clean config file & it seemed to have fixed mine. I also added the 7.8/3.2 patch. I'll put NukeSentinel on the site this weekend.

How could someone overwrite the config.php files unless they had the ftp password?
Find all posts by ssaceView user's profileSend private message
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12403


PostPosted: Mon Apr 10, 2006 8:10 pm Reply with quoteBack to top

Any number of ways, usually a vulnerability that allows uploading. Avoid old modules with security flaws, Coppermine, some Calendars, even some reported for vWar. Always keep your phpNuke updated with the Patched files and Sentinel

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
maho
Corporal
Corporal


Joined: Aug 15, 2004
Posts: 51


PostPosted: Tue Apr 11, 2006 12:44 am Reply with quoteBack to top

download your version of phpnuke and just replace index.php and that should do it.

Had same problems it was my fault leaving some folders to chmod 777

pm me if u need any help.....


also once u did that apply any security mods like sentinel etc ........
Find all posts by mahoView user's profileSend private message
omar3
Nuke Cadet
Nuke Cadet


Joined: Mar 08, 2006
Posts: 6


PostPosted: Tue Apr 11, 2006 2:37 am Reply with quoteBack to top

ScinergyIa wrote:
download your version of phpnuke and just replace index.php and that should do it.

Had same problems it was my fault leaving some folders to chmod 777

pm me if u need any help.....


also once u did that apply any security mods like sentinel etc ........


Can you be more specific while files/folders needs to be set with chmod?
and what are the correct settings?

What are the best tips or tricks to secure nuke?
Find all posts by omar3View user's profileSend private message
ssace
Lieutenant
Lieutenant


Joined: Dec 29, 2005
Posts: 175


PostPosted: Tue Apr 11, 2006 6:03 pm Reply with quoteBack to top

Thanks. Now that you mention it Evaders, he had vWar installed recently. He had the whole vWar folder chmoded to 777. That was prob the gateway.
Find all posts by ssaceView user's profileSend private message
kerman
Nuke Cadet
Nuke Cadet


Joined: May 05, 2006
Posts: 1


PostPosted: Sun May 07, 2006 6:27 pm Reply with quoteBack to top

I was hacked by this guys, and all they do was very simple:

Get admin account, and change the preferences (title, footer, etc) with a piece of code that print that text instead of yor home.

The solution was very simple: In Mysql, check the nuke_config table, or do a search of the word "defaced". Clear all this tables and its ok.

Hope it helps!
Find all posts by kermanView user's profileSend private message
afirca
Nuke Cadet
Nuke Cadet


Joined: Jun 17, 2006
Posts: 1


PostPosted: Sat Jun 17, 2006 2:01 pm Reply with quoteBack to top

You may watch how Wildboy does this hack from link below

interesting Smile
http://www.milw0rm.org/video/author/29#
Find all posts by afircaView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 1.021 Seconds - 261 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::