IndexScript Forum  

Go Back   IndexScript Forum > IndexScript > IndexScript - Directory Script
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
  #11  
Old 07-26-2007, 08:44 PM
rankappeal rankappeal is offline
Junior Member
 
Join Date: Apr 2007
Posts: 20
Default

Hi gkd_uk

The Fix Would not work before maybe due to me making changes to the original file to include an image. But I have managed to fix the fix so that i can have my image again without losing all subcats as stated in first post.
Reply With Quote
  #12  
Old 07-26-2007, 10:03 PM
patataur patataur is offline
Junior Member
 
Join Date: Apr 2007
Location: europe
Posts: 12
Default

thanks hakon
Reply With Quote
  #13  
Old 07-26-2007, 10:36 PM
colbyt colbyt is offline
Senior Member
 
Join Date: Sep 2006
Posts: 189
Default

Quote:
Originally Posted by Raven View Post
Mine was hacked too....over 2000 urls gone, and 100+ categories..gone.

--<Hacked by y0n4s >--

Is what it says in the title header

And I couldn't log in.

Thanks for this fix Hakon
Unless the hacker spent a lot of time manually deleting stuff, most likely the data is still there. Don't panic yet.

Try reinstalling the cats table only from backup and see if the data is still there.

Make a backup of the corrupt DB before you start, just in case.

Of course they could have done anything the admin could do from the admin panel. Just depends on how much time they wanted to spend doing it.
__________________
Colbyt
Reply With Quote
  #14  
Old 07-26-2007, 11:04 PM
Raven's Avatar
Raven Raven is offline
Moderator
 
Join Date: Jan 2007
Location: Oregon, USA
Posts: 155
Default

heh no they where gone. I re-inserted some of the cats from my test site and there where no errors saying that the cats already existed. I even looked at the dir_cat table first to see if they where still there or been deleted.

The only thing else they did in the admin panel was change the meta title, meta description and set the 'Stop accepting URLS' to 'Yes'...and thats it, I think I got lucky.
Reply With Quote
  #15  
Old 07-26-2007, 11:38 PM
_JB_ _JB_ is offline
Moderator
 
Join Date: Sep 2006
Posts: 126
Default

Hi all, well my sites were hacked again overnight. I've now applied the patch, cheers Hakon, hope it works OK.

This time the hacker did delete data as Raven experienced, they deleted dir_cat and more worringly dir_url.

Anyway I'm keeping my fingers crossed this time (plus backups have been taken)

JB
Reply With Quote
  #16  
Old 07-27-2007, 01:39 AM
rankappeal rankappeal is offline
Junior Member
 
Join Date: Apr 2007
Posts: 20
Default

I have noticed that quite a few indexscript web directories still have not been unhacked... Mostly the problem seems to be that cat names have only been changed, which is what happened to mine on wednesday this is easily fixed just rename your categories upload the new utils.php file and change your passwords.... The second and worst is what happened to my site on thursday they renamed my categories and other editable areas ie: meta tags with a redirect command taking me to that f**ing duck page in which case you need to download a backup of your data base and manually remove all the redirect commands then start a fresh data base... just a little bit more technical.. keep original copy at all times just in case.... when you are back up and running get back into admin and replace that what was corrupted..... LET THIS BE A STARK REMINDER TO BACKUP ON A REGULAR BASIS!! If anyone is in need of help with SQL backup files just IM me
Also my payment module settings where also changed

Last edited by rankappeal : 07-27-2007 at 01:45 AM.
Reply With Quote
  #17  
Old 07-27-2007, 05:49 AM
hakon hakon is offline
Administrator
 
Join Date: Jan 2006
Posts: 1,682
Default

thanks guys... there were 2 problems:

1. first was that the utils.php file had a function that is supposed to preparesql statements to avoid injection. however, there was a small hole in there which i tightened.

2. second was that although i had used that function in all the php files, i forgot to use that function in the other functions in the utils.php file itself.

bad coding on my part - sorry guys...

my site was hacked too... but they only changed category names... and was easy to recover. what what you guys posted, it seems that they deleted data in some of your directories...
__________________
Get your IndexScript skins HERE
Some other interesting sites: Pneumococcal Diseases | Learn about Colic | Pregnancy Articles | Humor Portal
Reply With Quote
  #18  
Old 07-27-2007, 10:05 AM
gkd_uk's Avatar
gkd_uk gkd_uk is offline
Moderator
 
Join Date: Mar 2007
Posts: 274
Default

Thanks for the fix Hakon

and thanks Colbyt for checking my site after I had applied the fix - thanks

Reply With Quote
  #19  
Old 07-27-2007, 10:37 AM
techpro techpro is offline
Member
 
Join Date: May 2007
Location: Cumbria UK
Posts: 72
Default

Yes, thanks for the fix. And timely perhaps to give a plug for my cPanel backup utility .

Hakon, if you want a copy, drop me a note and you can have a free reg code. I'm sure you back up already but the tool just makes it easier.
__________________
Julian Moss
Tech Directory - Ham Directory - Site Backup for cPanel

Last edited by techpro : 07-27-2007 at 10:39 AM.
Reply With Quote
  #20  
Old 07-27-2007, 10:39 AM
hakon hakon is offline
Administrator
 
Join Date: Jan 2006
Posts: 1,682
Default

colbyt has been a great help in identifying the problem... thanks!
__________________
Get your IndexScript skins HERE
Some other interesting sites: Pneumococcal Diseases | Learn about Colic | Pregnancy Articles | Humor Portal
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 04:20 AM.



Same Author: URL Shortening Script ]

Partners: IT Support Blog | Free Games | iWebzen Web Directory | PR Home Pages Web Directory ]





Powered by vBulletin® Version 3.6.9
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.