PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Installation & Upgrades

Photopost Pro Installation & Upgrades If you're having install or upgrade problems

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old October 16th, 2008, 06:57 PM   #1 (permalink)
Junior Member
Verified Customer
 
Join Date: Jul 2008
Posts: 1
Site hacked - please help prevent it again

Hello all,

Wanted to see if someone can tell me what happened to my vBGallery and more importantly how to prevent it in the future. I use version 6.11 and version 3.7.2 of VBulletin.

I noticed something was wrong where we went to the gallery and got a syntax error at line 3316 (admin line 153)

The files that were affected were:
adm-inc.php, adm-index.php, adm-misc.php and pp-inc.php.

Into these files someone inserted code similar to:
Code:
Content visible to verified customers only.
all had the code inserted before a
Code:
Content visible to verified customers only.
. adm-inc.php at line 153, adm-index.php at line 36, adn-misc.php at line 1077 and pp-inc.php at line 3316.

I'm guessing it's some kind of Javascript injection? What worries me is the
Code:
Content visible to verified customers only.
after which were urls for a bunch of my pages as well as a bunch of free drugs, women health, diets, etc. sites.

Any ideas on how to further secure my site would be appreciated. ( I realize I am not current for either vBulletin or vBGallery)

Thanks

Stan at scrappersworkshop.com
zippizip is offline   Reply With Quote
Old October 16th, 2008, 07:18 PM   #2 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
If the files themselves were hacked/modified; it sounds like someone got access to your server and was able to make changes to your files directly. I don't think this would have come from our software - can your host help identify how they got into your server to change the files?
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ebay Spoof - Site Hacked starman Photopost Pro Bug Reports 14 May 25th, 2007 05:14 PM
Help with hacked site katers Photopost Pro How Do I...? 10 February 27th, 2007 06:32 AM
PhotoPost 5.2 - I got hacked - how do I prevent this? Pauline Kenny Photopost Pro How Do I...? 16 October 17th, 2005 05:23 PM


All times are GMT -5. The time now is 11:57 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0