You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 53 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - First Hacking Attempt - Should I Take Any Measures? [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
nooz
Corporal
Corporal


Joined: Apr 07, 2005
Posts: 65


PostPosted: Wed Nov 02, 2005 1:28 pm Reply with quoteBack to top

got my first hacking attempt, should I take any further security measures?

I run Nuke Sentinel latest version 2.4a i think?? Anyway its the latest version... should I be worried at all?

heres what I was emailed...

Code:
Date & Time: 2005-11-02 07:32:45 EET GMT +0200
Blocked IP: 81.214.168.220
User ID: Anonymous (1)
Reason: Abuse-Author
--------------------
User Agent: Mozilla 4.0 (Linux)
Query String: www.mysite.co.uk/admin.php?op=AddAuthor&add_aid=i&add_name=Goda&add_pwd=x&add_email=xy@xy.com&add_radminsuper=1&admin=eCcgVU5JT04gU0VMRUNUIDEvKjox
Get String: www.mysite.co.uk/admin.php?op=AddAuthor&add_aid=i&add_name=Goda&add_pwd=x&add_email=xy@xy.com&add_radminsuper=1&admin=eCcgVU5JT04gU0VMRUNUIDEvKjox
Post String: www.mysite.co.uk/admin.php
Forwarded For: none
Client IP: none
Remote Address: 81.214.168.220
Remote Port: 4054
Request Method: POST


The IP belongs to Turk Telekom, they have no abuse email on their whois listing, how can I report this little Rainbow Brite wipe?
Find all posts by noozView user's profileSend private messageVisit poster's website
Xyberian
Colonel
Colonel


Joined: Mar 14, 2004
Posts: 1921

Location: Behind you

PostPosted: Wed Nov 02, 2005 2:22 pm Reply with quoteBack to top

1) First of all, ban that stupid guy's C class IPs.
2) Check your security patches (2.3.1 is very tough)
3) turn off all wysiwyg editor options if you turned on
4) sentinal is ok
5) change admin file name in your config.php file or you can move admin.php file to other directory.

That seems your phpnuke site is relatively secure and hack-proof.

Good Protection so far.

_________________
NukeKorea Dev. Network.
NukeKorea Laboratories
Find all posts by XyberianView user's profileSend private messageVisit poster's website
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.168 Seconds - 231 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::