Foren / Cotonti / Support / Hacked...

12NächsteLetzte

biro
#1 30. März 2009, 03:20
My site got hacked:http://www.cpelite.co.cc

what shall i do...
Be sure to check out<br /><br /><br />
My site-<a href="http://www.iso-center.co.cc">http://www.iso-center.co.cc</a><br />
My plugins;TPL Editior 1.2 &amp; Mobile site
gamer24.7
#2 30. März 2009, 03:31
By any chance do you know who did that?

You could report their IP
[b][color=#000000]Click [/color][url=http://www.design-studio.netau.net][color=#EF2929][u]Here[/u][/color][/url] [color=#F57900]For All You Design [/color][color=#756745]Related Needs.[/color][/b]
GHengeveld
#3 30. März 2009, 04:27
Do you know how this was achieved? Did they know your password or did you install a faulty plugin? It's not a good sign if Cotonti got hacked.. I know it can happen to any CMS but it's not exactly good for Cotonti's reputation.
rayblo
#4 30. März 2009, 04:36
The only part i can see is this ;

   <div class="text"><script language="javascript">
alert("That happens if you annoy a hacker.\nCPHaxer hacked you!\n\nThanks to Terminal ;)");
location.href = "http://www.google.com";
</script></div>
                    <div class="homeLink"><a href="http://www.cpelite.co.cc" title="Home">Home</a></div>
                </div>
            </div>
[b]www.dutchcotonti.com[/b]<br />
De plaats voor nederlandse ondersteuning voor Cotonti.<br />
The place for support for Cotonti in Dutch
robofreak111
#5 30. März 2009, 07:37
welll... did you annoy a hacker? or did you give out the cpanel info?
Trustmaster
#6 30. März 2009, 12:17
It is in {PHP.cfg.menu1}, so he's got your admin's password. Please let us know what plugins you use on your site. And don't forget to change the pass. Was it something easy to guess or bruteforce, by the way?
May the Source be with you!
biro
#7 30. März 2009, 21:54
if i delete php.cfg.menu1 from index.tpl will that message disappear
Be sure to check out<br /><br /><br />
My site-<a href="http://www.iso-center.co.cc">http://www.iso-center.co.cc</a><br />
My plugins;TPL Editior 1.2 &amp; Mobile site
Trustmaster
#8 30. März 2009, 21:58
Yes, it will. But better go to Admin => Config => Menu slots and edit the value there.
May the Source be with you!
biro
#9 30. März 2009, 22:38
i told u i cant login
Be sure to check out<br /><br /><br />
My site-<a href="http://www.iso-center.co.cc">http://www.iso-center.co.cc</a><br />
My plugins;TPL Editior 1.2 &amp; Mobile site
Kort
#10 30. März 2009, 22:58
use phpmyadmin to clean the slot. I believe cotonti is using same encryption method as seditio, so you can follow these instructions to reset your password:
http://neocrome.net/page.php?al=resetpass
SED.by - создание сайтов, разработка плагинов и тем для Котонти

Dieser Beitrag wurde von Kort (am 30. März 2009, 23:14, vor 15 Jahre) bearbeitet
biro
#11 31. März 2009, 03:42
OMG!!!!!!!!!!!!!i logged in finally

the reason was he cracked the second admins pass
Be sure to check out<br /><br /><br />
My site-<a href="http://www.iso-center.co.cc">http://www.iso-center.co.cc</a><br />
My plugins;TPL Editior 1.2 &amp; Mobile site
HarryRag
#12 31. März 2009, 05:03
Try this: http://xiodestudios.com/plug.php?e=safeadmin

and use some hard to guess passes
[center][url=<a href="">http://www.true-gamers.nl]True</a> &amp; Honest Gamers[/url][/center]
Kingsley
#13 31. März 2009, 05:35
# HarryRag : and use some hard to guess passes

Why is it that seditio/cotonti don't support punctuation marks? Imho it is a fairly simple way to make stronger passwords possible.
HarryRag
#14 31. März 2009, 05:43
hard passes for the save admin extra layer, so it's harder to get in ;-)
[center][url=<a href="">http://www.true-gamers.nl]True</a> &amp; Honest Gamers[/url][/center]
robofreak111
#15 31. März 2009, 05:57
Wow... thats a pretty cool plugin, im going to use it for my site, thx

12NächsteLetzte