<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Guestbook - almost extremely hacked"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "Guestbook - almost extremely hacked"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Guestbook - almost extremely hacked</title>
				<description><![CDATA[ Hi, I cant find any solution to my problem so here it goes:<br /> <br /> My guestbook at:<br /> [url]http://www.farbrortorsten.com/gastbok/[/url]<br /> is hacked.  <img src="https://proxy2.de/forum//images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" /> <br /> <br /> I still have my password and I can login to admin, but I cannot use the easy admin-page. When I try a black page with stupid text is shown for a while, then I get sent/redirected to www.cia.gov<br /> <br /> HTML was and still is disabled.<br /> <br /> Smilys were and are still on. All letters "e" is now shown as a vometing smily, and if change that in general settings a visit to my guestbook page will show the black page (mentioned above) instead of my brown page.<br /> <br /> After the attack I upgraded to version 2.3.1 but these problems remains. HELP PLEASE! <br />  <img src="https://proxy2.de/forum//images/smilies/499fd50bc713bfcdf2ab5a23c00c2d62.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14270.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14270.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 17:49:15]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Torsten"]Hi, I cant find any solution to my problem so here it goes:<br /> <br /> My guestbook at:<br /> [url]http://www.farbrortorsten.com/gastbok/[/url]<br /> is hacked.  <img src="https://proxy2.de/forum//images/smilies/9d71f0541cff0a302a0309c5079e8dee.gif" /> <br /> <br /> I still have my password and I can login to admin, but I cannot use the easy admin-page. When I try a black page with stupid text is shown for a while, then I get sent/redirected to www.cia.gov<br /> <br /> HTML was and still is disabled.<br /> <br /> Smilys were and are still on. All letters "e" is now shown as a vometing smily, and if change that in general settings a visit to my guestbook page will show the black page (mentioned above) instead of my brown page.<br /> <br /> After the attack I upgraded to version 2.3.1 but these problems remains. HELP PLEASE! <br />  <img src="https://proxy2.de/forum//images/smilies/499fd50bc713bfcdf2ab5a23c00c2d62.gif" />[/quote]<br /> <br /> Immediately after you open up your easy admin page to remove their post, press the "ESC" key you may need to do it several times to stop any sequences that they have coaded in. Once you are sure that the redirect is stalled by the Esc key, then delete normally. Keep HTML Disabled first and foremost - and do a search on this forum for other spam protective measures.  For example, I ended up including the words meta and script in my forbidden word section.  <br /> <br /> Good luck and let us know how it goes.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14271.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14271.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 18:01:03]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title>ok</title>
				<description><![CDATA[ Thanks, but I could only delete the last input. Now, before the easy admin page has loaded the edit and delete buttons the black hacker page arrives and sends me to www.cia.gov<br /> <br /> This screen shows how far I can come now:<br /> [url]http://www.farbrortorsten.com/temp/gb.jpg[/url]<br /> When I try to go to record number 102, 103 or 104 that black hacker page comes too quickly. <br />  <img src="https://proxy2.de/forum//images/smilies/1069449046bcd664c21db15b1dfedaee.gif"  /> <br /> <br /> I'm afraid I need another trick!]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14272.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14272.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 20:15:23]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Re-upload all the gb files again overwriting the ones there.<br /> Make backups of your templates before that.<br /> Re-upload original templates. Make modifications to the templates again.<br /> Look at the stickies in the support forum on how to patch your gb.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14273.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14273.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 20:37:05]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Auron and I posted about the same time - I would hold off actually uploading the gb again until you try the following <br /> <br /> Okay - the only other way to delete the post then is to go into your MySQL tables thru your Website's control panel (most use CPanel) - <br /> <br /> You will need to open the SQL tables for the guestbook - Some call it "MySQL Databases" or "MySQL Tools" while others call it "phpMyAdmin" - <br /> <br /> Look for the AGBook's tables to open then look inside that for "book_data"<br /> <br /> Once you open up book_data, you may need to click on "Browse" to find the list of table entries for your guestbook - you should be able to delete that one particular entry from there.  <br /> <br /> Some hackers have found a workaround within 2.3.1 that allows them to insert javascript codes, meta tags and redirects... I won't explain how it is done, but suffice it to say, I've found that making certain words "forbidden" helps.  for example, they used the smilies to enforce a redirect on your guestbook  [code] height=&quot;15&quot;&gt;nt=&quot;10;URL=http&#58;//www.cia.gov&quot;&gt;[/code]<br /> <br /> Good luck - and let us know if you need more help.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14274.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14274.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 20:46:20]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ OK for some reason everyone of your posts is messed up. They all now contain the puke smiley. Very bizarre. I wonder how they accessed your admin as you are not susceptible to the exploit. You should be able to login and access easy admin with no problems.<br /> <br /> EDIT - Oh I see somebody made it so that the puke face was posted wherever there was an e.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14276.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14276.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 20:58:24]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="ET"]Auron and I posted about the same time - I would hold off actually uploading the gb again until you try the following <br /> <br /> Okay - the only other way to delete the post then is to go into your MySQL tables thru your Website's control panel (most use CPanel) - <br /> <br /> You will need to open the SQL tables for the guestbook - Some call it "MySQL Databases" or "MySQL Tools" while others call it "phpMyAdmin" - <br /> <br /> Look for the AGBook's tables to open then look inside that for "book_data"<br /> <br /> Once you open up book_data, you may need to click on "Browse" to find the list of table entries for your guestbook - you should be able to delete that one particular entry from there.  <br /> <br /> Some hackers have found a workaround within 2.3.1 that allows them to insert javascript codes, meta tags and redirects... I won't explain how it is done, but suffice it to say, I've found that making certain words "forbidden" helps.  for example, they used the smilies to enforce a redirect on your guestbook  [code] height=&quot;15&quot;&gt;nt=&quot;10;URL=http&#58;//www.cia.gov&quot;&gt;[/code]<br /> <br /> Good luck - and let us know if you need more help.[/quote]<br /> <br /> reuploading files doesn't matter since all the entries are stored in the db.<br /> its just a case of fixing the smilie tags/whatever, and removing the offending entry/ies.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14285.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14285.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:29:31]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Smiley codes are stored in SQL. Give me admin access and I'll fix it in  minutes.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14286.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14286.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:30:52]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>:-)</title>
				<description><![CDATA[ Allright!  <img src="https://proxy2.de/forum//images/smilies/283a16da79f3aa23fe1025c96295f04f.gif" /> Thank you so much, especially ET! You outclassed the tech support of the company that hosts my site (they couldn't help me much)!<br /> <br /> I removed the crap through that phpMyAdmin thingy, and now my guestbook looks good.  <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" /> <br /> <br /> By some reason I had to remove the message (the previous record number 102), written by myself, to get back the normal look of the guestbook. But since they could changed so the puke smily appeared by the letter "e" maybe they can mess with the last input/record as well. <br /> <br /> I thought I already before the hacker attack had some good curse words to stop bad code, but I now have improved that list. <br /> <br /> Thanks again!<br /> <br /> <br /> [url]http://www.FarbrorTorsten.com/english.htm[/url]]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14287.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14287.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:41:56]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Auron"]<br /> reuploading files doesn't matter since all the entries are stored in the db.<br /> its just a case of fixing the smilie tags/whatever, and removing the offending entry/ies.[/quote]<br /> <br /> Auron - help me with the thinking here - how does loading the templates, etc, change the smilie tags and remove the offending entry? If I don't understand the thinking behind this, others may not understand it either....]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14288.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14288.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:43:31]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title>Re: :-)</title>
				<description><![CDATA[ [quote="Torsten"]<br /> By some reason I had to remove the message (the previous record number 102), written by myself, to get back the normal look of the guestbook. But since they could changed so the puke smily appeared by the letter "e" maybe they can mess with the last input/record as well. <br /> [/quote]<br /> <br /> Now that is interesting!!! Maybe chmod your templates files/dir back to 644 (rw-r--r--) for added security? I haven't seen them actually mess up other entries like that before.<br /> <br /> Anyways, glad you were able to fix the problem.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14289.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14289.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:52:54]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I'm wondering if they don't have access to either your guestbooks admin or MySQL database.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14290.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14290.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 22:53:15]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="ET"][quote="Auron"]<br /> reuploading files doesn't matter since all the entries are stored in the db.<br /> its just a case of fixing the smilie tags/whatever, and removing the offending entry/ies.[/quote]<br /> <br /> Auron - help me with the thinking here - how does loading the templates, etc, change the smilie tags and remove the offending entry? If I don't understand the thinking behind this, others may not understand it either....[/quote]<br /> <br /> one of the exploits of gb 2.3.1 was that they could access other files on the server, for example change some of the gb files like config.php etc.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14292.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14292.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 23:44:02]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Auron"]<br /> one of the exploits of gb 2.3.1 was that they could access other files on the server, for example change some of the gb files like config.php etc.[/quote]<br /> <br /> Thanks for helping me understand better.  Appreciated <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14294.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14294.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 23:47:47]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="ET"][quote="Auron"]<br /> one of the exploits of gb 2.3.1 was that they could access other files on the server, for example change some of the gb files like config.php etc.[/quote]<br /> <br /> Thanks for helping me understand better.  Appreciated <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" />[/quote]<br /> <br /> np, the thread where carb talked about is around here.<br /> maybe in the stickies? not sure though.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14296.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14296.php</link>
				<pubDate><![CDATA[Fri, 11 Feb 2005 23:58:01]]> GMT</pubDate>
				<author><![CDATA[ Auron]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ One you are in the admin section you can use the templates page to view any file on the server. You cannot edit them though unless they have been CHMOD'd to 777.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14307.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14307.php</link>
				<pubDate><![CDATA[Sat, 12 Feb 2005 12:07:16]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]One you are in the admin section you can use the templates page to view any file on the server. You cannot edit them though unless they have been CHMOD'd to 777.[/quote]<br /> <br /> hmmmmm.... maybe your server is set up a little differently than mine? Once I'm inside the admin section on the templates page, pages can be edited from admin if CHMOD is 777 OR 666 - so that was why I recommended to Torsten that the files CHMOD be 644 for his pages. But at this point, we don't know whether the hacker had access to his 2.3.1 version Admin or not....  Maybe we'll find out at a later time....]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14309.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14309.php</link>
				<pubDate><![CDATA[Sat, 12 Feb 2005 12:56:11]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I have now installed some patches för agbook 2.3.1 found on this forum. <br /> <br /> I looked in my file manager and all files in my guestbook drawer have the chmod 644, and the files have probably had that all the time. In easy admin I cannot change the templates (getting warnings), so I downloaded some of them to my computer with my ftp program so I could patch and redesign a little.<br /> <br /> Wonder what, if anything, the hacker can do now?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14310.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14310.php</link>
				<pubDate><![CDATA[Sat, 12 Feb 2005 13:05:03]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title>hacked guestbook</title>
				<description><![CDATA[ If you have been hacked CHANGE your database password.<br /> Edit your config.inc.php with your new password.<br /> Put a .htaccess password protection file in the admin folder.<br /> <br /> The Hackers are Editing the Database not the Guestbook.<br /> If you have not yet been hacked then <br /> Put a .htaccess password protection file in the admin folder<br /> <br /> This stops the hackers reading the config.inc.php file to get your dbs username and password.<br /> Just Deleting the entry and turning the smileys, html and other codes of will not stop the hackers.<br /> I know I have had my guestbook hacked 7 times. (the same guestbook)<br /> Also notice that when you remove the hacked entry you will lose your last valid guestbook entry as the hackers just overwrite the last entry in your guestbook.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14314.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14314.php</link>
				<pubDate><![CDATA[Sat, 12 Feb 2005 20:59:32]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ To be honest they can't usually do anything with your username and password as the MySQL server will be set up to only allow only connections from the server it is installed on. This is only a problem on shared hosting where they are on the same server.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14315.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14315.php</link>
				<pubDate><![CDATA[Sat, 12 Feb 2005 21:02:23]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>hacked guestbooks</title>
				<description><![CDATA[ Normally mySQL is only avalable to "localhost" but WHM/cPanel systesm seem to do funny things. <br /> I run myself (well I lost count) but a lot of sites and most of them use the Advanced Guestbook script.<br /> Apart from the hakers it's the best guestbook script on the net.<br /> but locking the admin folder with a .htaccess works a treat.<br /> I am guessing that they are using something in there to send there stupid html to the databse or using some sort of script to fool the server.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14325.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14325.php</link>
				<pubDate><![CDATA[Sun, 13 Feb 2005 05:38:14]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Yes cPanel is a pile of pants but I cannot see it being responsible for the recent defacements. If you have HTML enabled then they can post ANY HTML they wish. Also if you run 2.2 or updated from 2.2 to 2.3.1 but kept the 2.2. session.class.php file then they can log in as admin and when an edmin edits a post it is saved exactly as it is sent, complete with html tags.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14332.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14332.php</link>
				<pubDate><![CDATA[Sun, 13 Feb 2005 10:45:51]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>hmmm</title>
				<description><![CDATA[ I dont know where it comes from, but I have a .htacess file in my gb:s admin drawer. Guess I'm safe.  <img src="https://proxy2.de/forum//images/smilies/136dd33cba83140c7ce38db096d05aed.gif" /> <br /> <br /> Thanks for the help everybody!  <img src="https://proxy2.de/forum//images/smilies/97ada74b88049a6d50a6ed40898a03d7.gif" /> <br /> Goodnight!]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14337.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14337.php</link>
				<pubDate><![CDATA[Sun, 13 Feb 2005 22:46:30]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ the .htaccess file in admin folder is just to prevent the files from being viewed by a web browser. Well it's supposed to anyway.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4254/14338.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4254/14338.php</link>
				<pubDate><![CDATA[Sun, 13 Feb 2005 23:01:40]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
	</channel>
</rss>