Been hacked 3 times in the last month

17 years 8 months ago #19687 by pcgs
I've been hacked 3 times in the last month.

My hosting company has been pretty vauge about how all this was happening. The only thing they will tell me is that I need to update any PHP scripts I have running on my site. They told me if the hacking continues, they will suspend MY account. So I guess this means I cannot turn to them for help nor can I contact them to complain.

I want to put this anger I have about it to good use. So I'd like to learn more about how to protect myself. I would also like to learn how to determine just how these people are doing this too.

I am now using:

Joomla 1.0.10

Components:
CB 1.0.1 Stable
CbMailing
Joomlaboard 1.1.2
Mosets Tree 1.57
uddeIM 0.5b

Are there any modules I need to be concerned about? They don't have version numbers so its kind of hard to belive I would need to update them. I have to assume they run using scripting that cannot be updated.

What can I do to protect myself? Do I need to remove anything here? Thanks.

Please Log in to join the conversation.

17 years 8 months ago #19693 by masyomo

Please Log in to join the conversation.

17 years 8 months ago #19697 by pcgs
Replied by pcgs on topic Re:Been hacked 3 times in the last month
Thanks, this link is really helpful. I've been doing a lot of reading and see that "global registers" need to be off, but cannot find how to do it.

Is this in the admin area? If so where? If I need to alter a script, it is unclear which one to do. Thanks again.

Please Log in to join the conversation.

17 years 8 months ago #19810 by beat
Replied by beat on topic Re:Been hacked 3 times in the last month
search for "register_globals" on joomla forums. Plenty of information there.

Update to joomla 1.0.11, and in the new warning there is a link to the right thread.. ;)

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

17 years 8 months ago #19817 by gotMoxie
Replied by gotMoxie on topic Re:Been hacked 3 times in the last month
pcgs,

Definitely upgrade to Mosets Tree 1.59. There is a known security hole in Tree below 1.59 having to do with the Savant2 plug-ins.

Ain't security fun?

Post edited by: gotMoxie, at: 2006/08/29 19:46

Sam Lewis
Moxie Media, LLC

CB3PD

Please Log in to join the conversation.

17 years 8 months ago #19820 by pcgs
Replied by pcgs on topic Re:Been hacked 3 times in the last month

Ain't security fun?


Yeah, I'm sure having lots o' fun, whoopie! ;-)

And yes, I upgraded to Mosets Tree 1.59 yesterday.

I've been following the security postings in the Joomla forum. A growth experience for sure. My problem with is that the postings are kind of over my head. I read about .ini files, blocks of code to replace here and there, but often the person who posts assumes that everyone reading knows how and where these things need to be placed. There is a bit of shorthand that I need to get past. Also, we have to wade through pages and pages of postings to make sure that there is no new wrinkle at the end of the road.

Don't get me wrong, I am totally in debt to those who post and share their wealth of information. They are generous pioneers if not missionaries to those of us who sit at their feet to learn about the gospel of CMS.

I just wish there was one main location where the steps to certain procedures like, security procedures, upgrading, editing .htaccess files etc. could be posted to offer a straight through shot to a more step by step approach without the fragmentation of running commentary. I know the commentary can be very important, but it would be so nice to have an updated list of steps for certain tasks for the sake of reassurance that I haven't missed a step in my traveling through the threads.

Thanks for adding to my thread.

Post edited by: pcgs, at: 2006/08/29 20:30

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.178 seconds

Facebook Twitter LinkedIn