Results 1 to 10 of 26
Hybrid View
-
1st Oct 2009, 05:44 PM #1OPMember
Urgent Help Needed
Hi Friends I am Ashu, and i am in big trouble some hacker changed my ajax.php file and now he can execute any sql query through this file for security i have desabled all ajax features of my forum and also password protected this file so that he can't change anything coz through this file he can see my all root files & folders even he can edit them or he also view the codes thats why he know my database details from includes/config.php
I have upgrade my forum to 3.8.3 and replaced all file including ajax.php but problem still in there.
here is the screenshot what actually ajax.php showing (currently it is password protected)
http://i36.tinypic.com/2wd84tf.jpg
I have also found a site with same problem check here
http://www.technologyworksonline.com/democubecart/
So my friends i hope you will help me to get rid of form this problem.
Please please help me.
Regards,ashutariyal Reviewed by ashutariyal on . Urgent Help Needed Hi Friends I am Ashu, and i am in big trouble some hacker changed my ajax.php file and now he can execute any sql query through this file for security i have desabled all ajax features of my forum and also password protected this file so that he can't change anything coz through this file he can see my all root files & folders even he can edit them or he also view the codes thats why he know my database details from includes/config.php I have upgrade my forum to 3.8.3 and replaced all file Rating: 5
-
1st Oct 2009, 05:51 PM #2BannedWebsite's:
FusionWarez.info SmokeHost.net Leechers.coBro thats a shell. Replace it with your proper ajax.php file.
-
1st Oct 2009, 05:52 PM #3OPMember
Thanks bro for reply but I have already replaced it but the problem not gone.. and one more thing that what is "shell"
-
1st Oct 2009, 06:07 PM #4BannedWebsite's:
FusionWarez.info SmokeHost.net Leechers.coA shell is a file that is uploaded to a web server. And just by browsing to that file you can delete, rename, chmodd edit file contents. Download any file. Browse all files/folders on the webserver. And upload files. Also run malicious tools like fill hdd space etc. And run MySQL Queries.
-
1st Oct 2009, 06:15 PM #5ProbationWebsite's:
onlywarez.orgthing is he manged somehow to upload it to your webserver , if you allow uploading .php files then dont or this will happen over and over lol , maybe it is a bug in your current system check for exploits for it , you didnt give us information about what you were using ... , try to pin point the weak spot
-
1st Oct 2009, 06:18 PM #6BannedWebsite's:
Dev-Security.netWhat you need to do is contact your hyosting provider and secure there system from shells more he possibly uploaded it cause of a exploit on one of your scripts go and check them for any security issue.
-
1st Oct 2009, 06:34 PM #7Member
Maybe that guy had his password of cPanel and uploaded shells on many places ? , And named them with smart names not some random name like "r57" or "shell" ... Today on internet every kid has stealer , and It's so spreaded that almost everyone got infected. So I would suggest you to download your SQL database. And replace all vBulletin core files with new ones. And check file content of every folder of your skins directory.
Many sys admins aren't really smart enough to secure their server. So It would be just a fail , they would say Our server is secured , etc...
-
1st Oct 2009, 06:39 PM #8BannedWebsite's:
Dev-Security.netYes your right if that is the case then i reccomend the site owner to analayze each file and see if its a shell
-
1st Oct 2009, 06:42 PM #9BannedWebsite's:
FusionWarez.info SmokeHost.net Leechers.coHosting provider should definently use a webserver anti-virus and do a scan of his site's folder's.
-
1st Oct 2009, 06:44 PM #10BannedWebsite's:
Dev-Security.netIf the shell that has been uploaded encrypted clamAV wont even detect it and personally i dont even like clamAV its a big waist of memory
Sponsored Links
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
Urgent Help needed for PSD
By kelbri90 in forum Web Application/Script SupportReplies: 2Last Post: 27th Aug 2012, 07:49 PM -
Urgent help needed
By Th3Kill33r in forum Technical Help Desk SupportReplies: 5Last Post: 12th Nov 2010, 11:42 PM -
Urgent help needed please
By Th3Kill33r in forum vBulletinReplies: 0Last Post: 12th Nov 2010, 11:05 PM -
Some Urgent Help Needed
By Crazy4 in forum vBulletinReplies: 1Last Post: 23rd Dec 2009, 06:28 AM
themaCreator - create posts from...
Version 3.45 released. Open older version (or...