<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Guestbook hijacked"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "Guestbook hijacked"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Guestbook hijacked</title>
				<description><![CDATA[ Hi, I just discovered that the Advanced Guestbook of the site I managed gets redirected to some Turkish website <a class="snap_shots" href="http://www.mavideniz.org/" target="_blank" rel="nofollow">http://www.mavideniz.org/</a> .- I dont know these mean fellows, or how they accessed the files on my site to enable that process. <br /> <br /> The Guestbook script was installed via the CPanel. What can I do to get rid of the malicious script doing the redirection? I am new to PHP, and so I dont know where to look. I just could not locate anything alluding to that site in the index.php of the Guestbook.<br /> Please urgently help, as the website part of a big University website.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14694.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14694.php</link>
				<pubDate><![CDATA[Mon, 28 Feb 2005 23:47:59]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ THis link will take you to a thread where this happened and how to get into the database to remove it. <br /> <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=14274#14274" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=14274#14274</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14711.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14711.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 02:28:39]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Hi,<br /> Thanks for that response. I had actually just managed to solve the problem.<br /> Below is a comment I just made in another forum where I had also requested for help. The concerned database table, as also suggested in your forum articles was "book_data".<br /> <br /> I did actually go back to the database so I could prove to you what I had said, that there was no suspicious entry! This time, though, I opened the concerned database table in  PHPmyAdmin, in a different way, so it showed the entries in detail, and the re-directing script was hidden. I deleted and everything is now okay. Actually those bastards had put their script there as a "Comment" to the last visitors entry! For that reason, even the administration page of the Guestbook, where you could delete/edit the entries was not accessible as the same script would redirect me to the hackers page!<br /> <br /> <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif"/><br /> <br /> Is there anyway to prevent such?? <br /> Regards]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14722.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14722.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 14:21:34]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ turn off HTML and patch your guestbook.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14724.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14724.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 16:24:18]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Anonymous"]<br /> <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif"/><br /> <br /> Is there anyway to prevent such?? <br /> [/quote]<br /> <br /> I don't know - I can't find your guest book - the language is not something I understand on your site and you don't have it set up in a way that is intutive for me to find.  <br /> <br /> If you have version 2.2 - make certain to use the patch to fix the exploitable hole that allows backdoor access to the admin. <br /> <br /> And as Carbonize suggests, turn off HTML if you have it enabled on your guest book - perhaps password your comments - and as I had suggested in the other thread add those "words" to the curse words portion in the admin section to prevent people from even typing them into your guestbook. <br /> <br /> You can do these things if you have 2.2 or 2.3.1 versions of the guestbook.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14735.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14735.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 18:29:42]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ they didn't post a link to their site. the link they posted is one that many guestbooks have been redirected to.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14737.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14737.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 18:53:54]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Thanks Carbonize -  I should have picked up on that sooner... LOL]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/4336/14744.php</guid>
				<link>https://proxy2.de/forum/posts/preList/4336/14744.php</link>
				<pubDate><![CDATA[Tue, 1 Mar 2005 22:55:57]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
	</channel>
</rss>