i was hacked second time

Learn about Security for code and servers. Learn how to secure your site and your code. Learn about hacking prevention, finding and identifying exploits, and recognising vulnerabilities. Plus, Weekly Security tips and Tutorials.
Forum rules
Post questions related to security, analyse and learn about vulnerabilities and exploits within code to protect yourself against hackers.

i was hacked second time

Postby skyrfox » 13 Apr 2009, 07:59

please help me to secure my site.i'm novice in phpbb but i'm tired to see my work distroyed 2 times in one week.please sugestions...
skyrfox
Crewman
Crewman
 
Posts: 1
Joined: 13 Apr 2009, 07:07
Gender: Male
phpBB Knowledge: 1


Re: i was hacked second time

Postby wired076 » 14 Apr 2009, 07:10

Please advise version of phpBB used, php version, what modifications are installed.

Also what other software is installed on your site and are you on shared, vps, dedicated or some other type of hosting?

This is a hard question to ask anyone without them being able to study your setup in detail so any information you can give us will allow us to provide suggestions for you to implement.

As always you should always try and keep everything up to date on you server and do regular backups to prevent and minimise the stress/problems caused if/when this happens and to remove any easily hackable targets on the server.
I.T. Construct
STG Supporter
Please contact me via email/im for help at reasonable prices.
USA Based Web hosting
email: admin@itconstruct.com.au
- Visit http://www.itconstruct.com.au
wired076    
Supporter
Supporter
 
Posts: 494
Joined: 03 Feb 2009, 16:51
Location: Australia
Gender: Male
phpBB Knowledge: 5

Re: i was hacked second time

Postby Erik Frèrejean » 14 Apr 2009, 07:18

There are no know security issues with any phpBB 3 version at this moment. Therefore its most likely that this hacker entered your server through an other piece of software and exploited you through that. Please check whether all the software you are running is up to date with their latest version.
If you want to make sure that this isn't caused by phpBB you can submit a ticked to the phpbb.com IIT
ReadMe Before Posting / Frequently Asked Questions wrote:My board has been hacked, what do I do?
Please do the following before making any modifications to your board (this includes changing passwords, editing files, running the admin toolkit, etc.):
1) Save a copy of the files (simply create a local copy of the files on the server).
2) Save a copy of the database.
3) Save the server access logs for the time of the hack (they may be available in the 'logs' directory on the server, in your host's control panel or only by request directly from your host).
4) File a report in the incident tracker. Attach the items from steps 1-3 when you file the report or upload them to a secure location for the incident investigation team to download. Please do not start a new topic on the board, the proper place for incidents reports is the tracker.
Image Proud member of the phpBB support team
Image STG Support team member | Image STG Moderator team member
Image
User avatar
Erik Frèrejean    
phpBB Team Member
phpBB Team Member
 
Posts: 1114
Joined: 03 Dec 2007, 00:49
Location: USERS_TABLE
Favorite Team: New Orleans Saints
Gender: Male
phpBB Knowledge: 10


Return to Security Class

Who is online

Users browsing this forum: No registered users and 2 guests