Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

18504 Posts in 2408 Topics- by 848 Members - Latest Member: kabinet
Pages: [1] 2   Go Down
Print
Author Topic: scientist/ay  (Read 2230 times)
arkoomla
Full Member
***
Offline Offline

Posts: 110



View Profile
« on: 29.02.2008; 00:08:19 AM »

haknuta mi je stranica od navedenih iz naziva






haknuta mi je naslovna na kojoj je bila joomla na kojoj je bila samo jedna poruka, nista bitno, i neki testovi koji su bili, pord toga imam jos dva foruma, jedan od njih je za testiranja forumi su jos u funkciji.

sta se radi u ovakvim situcajama ?
jel moram bristai joomlu?
« Last Edit: 29.02.2008; 00:11:57 AM by arkoomla » Logged
nedim
Web Developer
SITE ADMIN
Hero Member
*
Offline Offline

Posts: 1448



View Profile WWW
« Reply #1 on: 29.02.2008; 00:35:08 AM »

Ma jok, samo zamijeni index.php fajl.
Vjerovatno je imao premisije 777.
Logged

arkoomla
Full Member
***
Offline Offline

Posts: 110



View Profile
« Reply #2 on: 29.02.2008; 00:46:20 AM »

nije ima premisije 777, sta znaci zamijeni? u ftp-u? ako da, do sam uradio i isto  Sad
Logged
nedim
Web Developer
SITE ADMIN
Hero Member
*
Offline Offline

Posts: 1448



View Profile WWW
« Reply #3 on: 29.02.2008; 00:56:30 AM »

Pa znam onda sta je.
Pregleda configuration.php fajl, vidi da u njemu ne povlace neke druge podatke.
Overwrituj fajlove koji se vec nalaze u joomla instalaciji tj zamjeni ih novima cistima.
To bi moralo da rijesi problem.
Logged

sin2384
GLOBAL MODERATOR
Hero Member
*
Offline Offline

Posts: 1288



View Profile WWW
« Reply #4 on: 29.02.2008; 03:40:12 AM »

I pročitaš ovo:
http://help.joomla.org/component/option,com_easyfaq/task,view/id,167/Itemid,268/
Logged

Hellas
Sr. Member
****
Offline Offline

Posts: 383



View Profile WWW
« Reply #5 on: 29.02.2008; 04:06:05 AM »

mene zanima koju si joomla-u imao
koje komponente i koliko stare?
jesi uspio da utvrdis nacin kako su te haknuli?
Logged

arkoomla
Full Member
***
Offline Offline

Posts: 110



View Profile
« Reply #6 on: 29.02.2008; 04:59:57 AM »

bila je zadnja stabila 1.0.14 nije bilo nikakvih komponenti, samo dva linka u meniju "home" i "forum" i jedna slika kao obavjestenje userima.

nisam nista saznao kako su haknuli sajt, posto nista na njemu nije bilo vrijdno izbrisao sam joolu i hajd ne zalim za tim, ali ne znam sta uraditi da se opet ne desi. folder u kojem se nalazila joomla je (nisam siguran kako se to zovew chmodovan? Embarrassed Embarrassed) 750 jel do toga?
Logged
Bojan
Web Dizajner
GLOBAL MODERATOR
Full Member
*
Offline Offline

Posts: 143


I love linux!


View Profile WWW
« Reply #7 on: 01.03.2008; 21:46:05 PM »

Quote
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<title>Hacked BY Scientist/AYT</title>
<style type="text/css">
<!--
body,td,th {
   color: #FFFFFF;
}
body {
   background-color: #000000;
}
.style3 {
   font-size: xx-large;
   font-weight: bold;
   font-family: "Courier New", Courier, monospace;
}
-->
</style></head>

<body>
<EMBED src=http://dosyalar.semazen.net/muzic/Esma1.mp3   width=0 height=0 type=audio/x-ms-wma>
<center>
  <span class="style3">HACKED BY SCIENTIST/AYT</span>
</center>
<center></center>
</body>
</html>
to mi stoji u configuration.php
Logged

Bojan
Web Dizajner
GLOBAL MODERATOR
Full Member
*
Offline Offline

Posts: 143


I love linux!


View Profile WWW
« Reply #8 on: 01.03.2008; 21:48:44 PM »

gdje da zbavim stari configuration.php?
Logged

Hellas
Sr. Member
****
Offline Offline

Posts: 383



View Profile WWW
« Reply #9 on: 01.03.2008; 22:25:15 PM »

gdje da zbavim stari configuration.php?

imas li jsas? instaliraj i pokupi odatle samo modificaraj da pase novom serveru.
*****te odoh ja da radim upgrade kod sebe na 1.0.15... backup sam odradio zasad.
 
da li je moguce i vjerovatnije da nije upad preko joomla-e nego ako si shared hostingu preko nekog drugog?

da li je ta zadnja bila instalirana na cisto ili je bila upgrade na neku stariju
kod mene su sve bile od 1.0.13 osim jedne i sve imaju navedenu izmjenu

Quote
Web sites created with Joomla! 1.0.13 or later already contain this line. However, Web sites upgraded from 1.0.12 or earlier are missing this line. All this upgrade does is add that line to the configuration.php file if that line does not already exist. Another way to address the vulnerability is to simply add the line to your configuration.php file manually.
« Last Edit: 01.03.2008; 22:36:52 PM by Hellas » Logged

fantastic
SITE ADMIN
Hero Member
*
Offline Offline

Posts: 1272



View Profile WWW
« Reply #10 on: 01.03.2008; 22:59:39 PM »

Postavi configuration.php fajl iz nove instalacije joomle a zatim izmijeni parametre.

Mislim da je problem bio do Joomle 1.0.13/1.0.14
Logged

Bojan
Web Dizajner
GLOBAL MODERATOR
Full Member
*
Offline Offline

Posts: 143


I love linux!


View Profile WWW
« Reply #11 on: 02.03.2008; 00:54:28 AM »

Odradio, ali sada se javlja drugi problem...



« Last Edit: 21.03.2008; 22:48:41 PM by Bojan » Logged

nedim
Web Developer
SITE ADMIN
Hero Member
*
Offline Offline

Posts: 1448



View Profile WWW
« Reply #12 on: 02.03.2008; 01:06:55 AM »

Kopiraj fajl version.php iz instalacije joomle u direktorij /home2/nenodoo/public_html/dobrodosli/includes .
To bi trebalo rijesiti problem.
Logged

fantastic
SITE ADMIN
Hero Member
*
Offline Offline

Posts: 1272



View Profile WWW
« Reply #13 on: 02.03.2008; 02:16:29 AM »

Odradio, ali sada se javlja drugi problem...



Quote
Warning: require_once(/home2/nenodoo/public_html/dobrodosli/includes/version.php) [function.require-once]: failed to open stream: No such file or directory in /home/nenodoo/public_html/dobrodosli/includes/joomla.php on line 71

Fatal error: require_once() [function.require]: Failed opening required '/home2/nenodoo/public_html/dobrodosli/includes/version.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/nenodoo/public_html/dobrodosli/includes/joomla.php on line 71

Pogledaj sta je postavljeno za livesite u configuration.php
Logged

arkoomla
Full Member
***
Offline Offline

Posts: 110



View Profile
« Reply #14 on: 15.03.2008; 01:59:26 AM »

a jesu se ovi turci okomili na mene Sad evo opet mi hakirali i joomlu i phpbb3
"HACKED BY SCIENTIST AYYILDIZ TEAM 57.ALAY"
??? koji im je k...
Logged
Pages: [1] 2   Go Up
Print
Jump to: