Did I get hacked?!? -*Ipowerweb issue:Hack or MYsql problem?

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785
Locked
blykmik
Registered User
Posts: 40
Joined: Sat Jun 18, 2005 4:38 am
Contact:

Did I get hacked?!? -*Ipowerweb issue:Hack or MYsql problem?

Post by blykmik » Fri Jul 01, 2005 7:28 pm

I just installed phpBB last night (version 2.0.16).

I added only easyMOD and the tabulated survery mod...

The forum seemed to be working great... everything was up and running...

When suddenly today, I get Unknown failed to open stream and Warning: (null) (): failed opening erros when attempting to access the forums.

I went into my ftp client to figure out what is going on and noticed that a good number of my files have had their permissions changed to 000 (instead of 644)..

index.php
posting.php
viewforum.php
etc, etc

I am unable to change the permissions on these files and when I open them, the are empty except for the following text:

upgrade this script. This script could be exploited

So... it seems like a hack to me.

*Note, as I am typing this, I got a hold of my hosting company. They are telling me that there is a "server wide hack" that got into the forums... They say I'm not the only one affected... BUT, This seems a little suspect to me since I just installed this board last night and just gave a public link to it at about 1am.

I want to know who could possibly get to my files and delete them like that...

Does anyone know what might be going on here?[/b]

Are my users gone and deleted?
Last edited by blykmik on Fri Jul 01, 2005 8:04 pm, edited 3 times in total.

BayStateDubs
Registered User
Posts: 5
Joined: Wed Jun 15, 2005 3:38 am

Post by BayStateDubs » Fri Jul 01, 2005 7:32 pm

BUMP

I'd like to know as well because the same thing happened to my boards :oops:

Brandyn
Registered User
Posts: 43
Joined: Fri Apr 18, 2003 10:46 pm
Contact:

Post by Brandyn » Fri Jul 01, 2005 7:38 pm

same thing here as well. was it something like this?

Warning: Unknown(/home/reelfish/public_html/forums/index.php): failed to open stream: Permission denied in Unknown on line 0

Warning: Unknown(/home/reelfish/public_html/forums/index.php): failed to open stream: Permission denied in Unknown on line 0

Warning: (null)(): Failed opening '/home/reelfish/public_html/forums/index.php' for inclusion (include_path='.:/usr/local/lib/php') in Unknown on line 0

doriath_FK
Registered User
Posts: 5
Joined: Fri Jul 01, 2005 7:31 pm

Post by doriath_FK » Fri Jul 01, 2005 7:39 pm

And same here... :roll:

ExtremeGL
Registered User
Posts: 207
Joined: Sun Jun 05, 2005 12:05 am
Location: the North Pole!
Contact:

Post by ExtremeGL » Fri Jul 01, 2005 7:39 pm

I got that too! What's goin' on?!
--Alex--
Merry Christmas!

blykmik
Registered User
Posts: 40
Joined: Sat Jun 18, 2005 4:38 am
Contact:

Post by blykmik » Fri Jul 01, 2005 7:40 pm

I have the same errors too.. What is your hosting company?

Also... did you look at your files and see if they have had all the code erased and replaced with the same message?

"upgrade this script. This script could be exploited"

Keep us posted...

CSA_E_Law
Registered User
Posts: 40
Joined: Tue Jan 27, 2004 1:36 am

Post by CSA_E_Law » Fri Jul 01, 2005 7:41 pm

look at the files, someone hacked them....

doriath_FK
Registered User
Posts: 5
Joined: Fri Jul 01, 2005 7:31 pm

Post by doriath_FK » Fri Jul 01, 2005 7:42 pm

Yes, some files are updated, with permission 000, cant even owerwrite...

ExtremeGL
Registered User
Posts: 207
Joined: Sun Jun 05, 2005 12:05 am
Location: the North Pole!
Contact:

Post by ExtremeGL » Fri Jul 01, 2005 7:42 pm

Noooooooo... :cry:
--Alex--
Merry Christmas!

CSA_E_Law
Registered User
Posts: 40
Joined: Tue Jan 27, 2004 1:36 am

Post by CSA_E_Law » Fri Jul 01, 2005 7:42 pm

yeah neither can anyone, i contacted my server provider, waiting on them.

blykmik
Registered User
Posts: 40
Joined: Sat Jun 18, 2005 4:38 am
Contact:

Post by blykmik » Fri Jul 01, 2005 7:46 pm

Who's is everyone's hosting company?

Mine is ipowerweb.com and they said they've been hacked when I called them on the phone...

This really sucks.

ExtremeGL
Registered User
Posts: 207
Joined: Sun Jun 05, 2005 12:05 am
Location: the North Pole!
Contact:

Post by ExtremeGL » Fri Jul 01, 2005 7:47 pm

Mine's ipowerweb....
--Alex--
Merry Christmas!

Katie Pie
Registered User
Posts: 165
Joined: Fri Apr 25, 2003 10:52 pm
Location: Bollnäs, Sweden
Contact:

Post by Katie Pie » Fri Jul 01, 2005 7:49 pm

I have StartLogic and I got the same problem.

CSA_E_Law
Registered User
Posts: 40
Joined: Tue Jan 27, 2004 1:36 am

Post by CSA_E_Law » Fri Jul 01, 2005 7:49 pm

the good news is the database is not touched. So its not that bad.

blykmik
Registered User
Posts: 40
Joined: Sat Jun 18, 2005 4:38 am
Contact:

Post by blykmik » Fri Jul 01, 2005 7:50 pm

from the look of it, it seems like it is all ipowerweb customers...

everyone's directory structure (in the error message) looks the same.

Locked

Return to “2.0.x Support Forum”