<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "HACKED!!!!!!!!!"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "HACKED!!!!!!!!!"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>HACKED!!!!!!!!!</title>
				<description><![CDATA[ <img src="https://proxy2.de/forum//images/smilies/c30b4198e0907b23b8246bdd52aa1c3c.gif" /> <br /> <br /> <a class="snap_shots" href="http://www.39reasons.com/guestbook39/" target="_blank" rel="nofollow">http://www.39reasons.com/guestbook39/</a><br /> <br /> I'm pretty new at all this. I've done the search for fixing it, but I'm just not sure I understand it enough and don't want to make it worse.  <img src="https://proxy2.de/forum//images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" /><br /> <br /> I can still log into my admin pages - but I don't know what to do from there.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11173.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11173.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 08:28:36]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ looks like they edited the header.php in the templates file or possibly body.php I doubt they did this via the guestbook though. Did you chmod the template files to 777? Possibly this person has an account on the same server as you. Simply remove the cde from the appropriate template file.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11180.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11180.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 12:38:10]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ He is running version 2.3.1 also.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11181.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11181.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 13:37:29]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title>I upgraded after the fact</title>
				<description><![CDATA[ I upgraded to 2.3.1 after reading all of the suggestions on here.  Like I said, I'm pretty new to this so I'm not sure what [quote]Did you chmod the template files to 777[/quote] means.  <img src="https://proxy2.de/forum//images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" /> <br /> <br /> This is what my header template looks like - again, I don't know a lot about coding, but I'm trying to learn.   <br /> <br /> &lt;html&gt;<br /> &lt;head&gt;<br /> &lt;title&gt;$LANG[FormSelect]&lt;/title&gt;<br /> $LANG[metatag]<br /> &lt;meta name="keywords" content="guestbook, php, script, mySQL, free, advance"&gt;<br /> &lt;style type="text/css"&gt;<br /> &lt;!--<br /> .font1 {  font-family: $VARS[font_face]; font-size: $VARS[tb_font_1]; color: $VARS[text_color] }<br /> .font2 {  font-family: $VARS[font_face]; font-size: $VARS[tb_font_2]; color: $VARS[text_color] }<br /> .font3 { font-family: Arial, Helvetica, sans-serif; font-size: 7.5pt; color: $VARS[text_color]; font-weight: bold}<br /> .select {  font-family: $VARS[font_face]; font-size: 9pt}<br /> .input {  font-family: $VARS[font_face]; font-size: 9pt}<br /> --&gt;<br /> &lt;/style&gt;<br /> &lt;script language="JavaScript"&gt;<br /> &lt;!--<br /> function gb_picture(Image,imgWidth,imgHeight) {<br />     var border = 24;<br />     var img = Image;<br />     var features;<br />     var w;<br />     var h;<br />     winWidth = (imgWidth&lt;100) ? 100 : imgWidth+border;<br />     winHeight = (imgHeight&lt;100) ? 100 : imgHeight+border;<br />     if (imgWidth+border &gt; screen.width) {<br />         winWidth = screen.width-10;<br />         w = (screen.width - winWidth)/2;<br />         features = "scrollbars=yes";      <br />     } else {<br />         w = (screen.width - (imgWidth+border))/2;<br />     }<br />     if (imgHeight+border &gt; screen.height) {<br />         winHeight = screen.height-60;<br />         h = 0;<br />         features = "scrollbars=yes";      <br />     } else {<br />         h = (screen.height - (imgHeight+border))/2 - 20;<br />     }<br />     winName = (img.indexOf("t_") == -1) ? img.substr(4,(img.length-<img src="https://proxy2.de/forum//images/smilies/b2eb59423fbf5fa39342041237025880.gif"  />) : img.substr(6,(img.length-10));<br />     features = features+',toolbar=no,width='+winWidth+',height='+winHeight+',top='+h+',left='+w;<br />     theURL = '$GB_PG[base_url]/picture.php?img='+Image;<br />     popup = window.open(theURL,winName,features);<br />     popup.focus();  <br /> }<br /> //--&gt;<br /> &lt;/script&gt;<br /> &lt;/head&gt;<br /> &lt;body bgcolor="$VARS[pbgcolor]" link="$VARS[link_color]" vlink="$VARS[link_color]"&gt;<br /> <br /> Thanks!!!<br /> Pamela]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11185.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11185.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 17:12:33]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Sorry my mistake. They have editted a post via the admin area. The exploit for the guestbook does not work on your site though so I am curious as to how they got in. Anyway you can delete the post that got editted to fix the problem then change your password. Or if you wish email me the login details and I will deal with it. My email is on my site.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11186.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11186.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 18:04:30]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Chmod is changing file permissions.  Here is a post explaining it, you might want to read later:<br /> <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3520" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3520</a><br /> <br /> This post explains how to change permissions from the CPanel:<br /> <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3654" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3654</a> (second from last post)<br /> <br /> <br /> I don't think any of that will help you get rid of the hack.  You need to find the offense and delete it... either from one of the template files or the Easy Admin Panel.  If you email the login, I could try to find it for you.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11187.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11187.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 18:06:43]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title>Thank you thank you thank you!!!!</title>
				<description><![CDATA[ [quote="Carbonize"]Sorry my mistake. They have editted a post via the admin area. The exploit for the guestbook does not work on your site though so I am curious as to how they got in. Anyway you can delete the post that got editted to fix the problem then change your password. Or if you wish email me the login details and I will deal with it. My email is on my site.[/quote]<br /> <br /> Carbonize - you are a genius!!!   <img src="https://proxy2.de/forum//images/smilies/283a16da79f3aa23fe1025c96295f04f.gif" /> I went in through myphpAdmin page - checked the latest entry - and sure enough - that was the problem!!!  So I deleted it, and I'm back up and running.  Thank you everyone!!  And amber... I will read that post you suggested too.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11188.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11188.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 19:09:36]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ glad to have helped. You could of just as easily deleted the post using the admin section of the guestbook but it was probably easier to identify the entry via phpMyAdmin. <br /> <br /> I'm still curious as to how they gained access so as I said change your password.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11189.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11189.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 19:13:47]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Actually - that was the first place I went once I knew I still had access to my admin section.  But the photo was showing up so huge even in there (like it was on the guestbook itself) that I couldn't get to the message to delete it.  It was in message 94 or 95 - and the photo covered everything down to message 80.<br /> <br /> And since this happened, I have upgraded to the newer version of the guestbook AND changed my password!  <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11190.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11190.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 19:36:13]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ No problems with using the admin section after you upgraded? There is a known bug whereby you end up in a login loop when trying to use the admin section after upgrading from 2.2 to 2.3.1.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11191.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11191.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 20:37:51]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>Nope</title>
				<description><![CDATA[ No problems.  I am able to log in with no problem. Haven't done anything but delete the testing posts - but so far so good.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11194.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11194.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 22:11:39]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Glad to hear it. You may also want to use my image verification mod to prevent sutomated spamming of your guestbook. Not that I saw any. <br /> <br /> Just a suggestion, why not edit the templates a little so that you could have the guestbook load in the iframe you use for the rest of the site?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11195.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11195.php</link>
				<pubDate><![CDATA[Tue, 26 Oct 2004 22:24:19]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]Glad to hear it. You may also want to use my image verification mod to prevent sutomated spamming of your guestbook. Not that I saw any. [/quote]<br /> <br /> where would I find that?<br /> <br /> [quote="Carbonize"]Just a suggestion, why not edit the templates a little so that you could have the guestbook load in the iframe you use for the rest of the site?[/quote]<br /> <br /> Would love to..... but don't know how  <img src="https://proxy2.de/forum//images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" />   And I don't want to bother anyone with it.  I don't handle the majority of the site, only the extras (guestbook,  e-mail, stats and CPanel maintenance) and our "webmaster"  <img src="https://proxy2.de/forum//images/smilies/69934afc394145350659cd7add244ca9.gif" /> is still learning how to do this as well.  There are other things I want to (eventually) figure out how to do - get rid of the "here you can leave your mark" note, replace the "GUESTBOOK" image with our logo, have that link return the viewer back to the main site, fun stuff like that.  I know all those answers are on this forum somewhere, I just need to find the time to research them. Plus I need to figure out how to allow visitors to the site the option of signing up on our mailing list...... want to add an online journal for the guys in the band to post into... I could go on and on and on and on.... but I won't   <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" /><br /> <br /> Just want to thank you all again for your help - don't know what I would have done without this forum.    <img src="https://proxy2.de/forum//images/smilies/283a16da79f3aa23fe1025c96295f04f.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11207.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11207.php</link>
				<pubDate><![CDATA[Wed, 27 Oct 2004 04:43:31]]> GMT</pubDate>
				<author><![CDATA[ 39 Reasons]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ <a class="snap_shots" href="http://www.carbonize.co.uk/verification.zip" target="_blank" rel="nofollow">www.carbonize.co.uk/verification.zip</a> for the image verification. Most of the guestbooks text can be editted via the lang/english.php file. The HTML is to be found in the templates folder.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11213.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11213.php</link>
				<pubDate><![CDATA[Wed, 27 Oct 2004 09:46:57]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>Hacked and no entry</title>
				<description><![CDATA[ Hi guys,<br /> Okay... so what if we've been hacked and we can't access our Admin?<br /> Our passwords have been changed.  How do we hack back in?<br /> <br /> We can get into the control panel and php pages, but can't seem to get to anything that resembles the guest entries to be able to delete the damned hacker.<br /> <br /> We're at [url]http://grahamgreene.topcities.com/guestbook[/url]<br /> <br /> Any tips?<br /> <br /> Thanks... I hope.<br /> [b][color="violet"]Dusky[/color][/b].]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11269.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11269.php</link>
				<pubDate><![CDATA[Thu, 28 Oct 2004 17:22:08]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ You can reset the password by editing the SQL data. If your host provides you with phpMyAdmin then simply login and change the username and password entries. Change the username to anything you want and put 773359240eb9a1d9 as the password, this will make the password 123.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11270.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11270.php</link>
				<pubDate><![CDATA[Thu, 28 Oct 2004 18:09:37]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>Nope it's all good</title>
				<description><![CDATA[ Awesome website... walked around and followed the arrows...<br /> <br /> Sorted the problem out now.<br /> <br /> Thanks, (meaningfully)<br />  <img src="https://proxy2.de/forum//images/smilies/8a80c6485cd926be453217d59a84a888.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11274.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11274.php</link>
				<pubDate><![CDATA[Thu, 28 Oct 2004 18:42:40]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Hope you changed the password to something different than last time.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3767/11276.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3767/11276.php</link>
				<pubDate><![CDATA[Thu, 28 Oct 2004 18:50:33]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
	</channel>
</rss>