hacked
Moderator: RLG MGMT Team
hacked
my server was hacked this morning. it initially looks like a combination of the file upload service in this portal and a vulnerability in php. i have disabled the file upload section of this portal for now, and will probablyn look for an alternative in the near future. the hacker did delete all files in the files.rlgaming.com site - so if you have something you need there let me know and we will see about recreating.
Helmut
- PanzerMeyer
- Posts: 4795
- Joined: 10 Feb 2004, 08:54
- Location: Miami, Florida
- Tach Deneva
- Posts: 1546
- Joined: 18 Dec 2002, 18:51
- Location: KY
- Tach Deneva
- Posts: 1546
- Joined: 18 Dec 2002, 18:51
- Location: KY
the hack was a vulnerability in the pafilesdb applet that comes with the portal we are using. it allowed remote execution of files on another server as if they were on this one. very sophisticated, and if not so malicious is a very cool script. it is the C99shell script. i am sure you can google it, but once a friend helped me figure it out i ran it myself and it shows EVERYTHING on the server.
Helmut
no, not likely. no more uploading of avatars, etc. i will also be turning off html in posts - will have to use bbcode. uploading capability is what allowed the hacker in, so no more.
these forums will be upgraded at the earliest convenience to phpBB3 as well.
these will not be back to 100% as they were. it will end up being just plain forums. files will have to be uploaded with either ftp or scp (i prefer the latter, and there are free client tools). they will all be located on files.rlgaming.com.
not sure if the C99shell allows root access, but several web sites on the server were hacked. may as well have had root access.
these forums will be upgraded at the earliest convenience to phpBB3 as well.
these will not be back to 100% as they were. it will end up being just plain forums. files will have to be uploaded with either ftp or scp (i prefer the latter, and there are free client tools). they will all be located on files.rlgaming.com.
not sure if the C99shell allows root access, but several web sites on the server were hacked. may as well have had root access.
Helmut