gokay turk hacker virus! help!

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785
massimomassimo
Registered User
Posts: 15
Joined: Sat Oct 11, 2003 7:51 pm

gokay turk hacker virus! help!

Post by massimomassimo »

hi there, my forum www.tsnk.co.uk/phpBB2 has been hacked and wondered how i can solve this without losing all my posts? i have/had alot of important information on there and it seems to have erased all the posts but i have a feeling its just 'hidden' and can be recovered. i havnt done a back up before, yes i know that was stupid of me!!!

if you look on my website you can see that hes put up an image, soundfile, renamed my forum to 'hacked by gok-kay' and erased all posts except for polls (why!?!?!?!). i did a search on google and other peoples forums have been hacked (though not that many forums) and each forum has a different image/animation and some even a video file.

thank you very much for your help

Massimo

massimomassimo
Registered User
Posts: 15
Joined: Sat Oct 11, 2003 7:51 pm

Post by massimomassimo »

also, i cant log into administration.the button is missing,

User avatar
KevC
Support Team Member
Support Team Member
Posts: 69899
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Post by KevC »

One thing to do is back up your databases and the config.php (this has the link info to the databases) file before you start.

You can get to the databases through phpmyadmin (in your server site control panel).

You can also install the starfox toolkit (linked in my sig) and make yourself an admin again and delete anyone who is an admin that shouldn't be.
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"

massimomassimo
Registered User
Posts: 15
Joined: Sat Oct 11, 2003 7:51 pm

Post by massimomassimo »

ok , but what do you mean 'before i start' ? what should i be starting?

ill try what you said when i get home- im just at work! any other advice??

User avatar
KevC
Support Team Member
Support Team Member
Posts: 69899
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Post by KevC »

Start fixing and updating.
You got hacked because you're on v2.0.11 and the current one is 2.0.17.

Basically what you can do is download the 2.0.17 version and upload everything except the config.php, install and contrib folders (you'll have to run the update_to_latest.php file in the changefile zip as well).

That will update the forum but you'll lose any MODs you have.

More info here
http://www.phpbb.com/kb/article.php?article_id=271
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"

Stung
Registered User
Posts: 4
Joined: Tue Jul 05, 2005 2:39 am

Post by Stung »

Hi,

I've been hacked too. I think it's from some Turkish thing because of the language left on the messageboard. It is at http://www.flyingsams.com/forum. I would like to upgrade, but my board is heavily modded. Do I have to reinstall all the modifications when I upgrade? If I do, what is the easiest way to do so?

Thank you.

User avatar
KevC
Support Team Member
Support Team Member
Posts: 69899
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Post by KevC »

You can get the change files from here
http://www.phpbb.com/phpBB/catdb.php?cat=48

Do stepwise upgrades eg 2.0.10>11 then 11>12 etc etc.

You can install them with easyMOD.
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"

Myztri
Registered User
Posts: 14
Joined: Tue Sep 21, 2004 8:25 pm
Location: Texas
Contact:

Post by Myztri »

I too got this. It was an error on my part, by not noticing an upgrade, and by not having a backup file that would do any good.
I simply started over, but am now having an odd error.
The stupid thing deletes posts, and deleted the admin account. Nothing I could do without the proper files to restore, so i started fresh.

User avatar
Mike2737
Registered User
Posts: 76
Joined: Sat Oct 01, 2005 12:58 am
Location: Earth

phpbb boards easily hacked

Post by Mike2737 »

There sure are a lot of hacked phpbb boards.

From what i've seen phpbb users are very easily susceptible to being hacked, for whatever reason. This is the only board i've ever used where every day i see a member posting about how he's been hacked.

This is frightening to a new user like myself.

:(

User avatar
jwunderly
Registered User
Posts: 5740
Joined: Sun Mar 30, 2003 2:18 pm
Location: Easton, PA (in the groove)

Re: phpbb boards easily hacked

Post by jwunderly »

Mike2737 wrote: There sure are a lot of hacked phpbb boards.

From what i've seen phpbb users are very easily susceptible to being hacked, for whatever reason. This is the only board i've ever used where every day i see a member posting about how he's been hacked.

This is frightening to a new user like myself.

:(


There sure are a lot of people who just install a board and then never (or rarely) do any maintenance on it. All you have to do is keep updated. Sign up for the e-mail notification here under the Support Menu. When a new version is released, everyone who subscribes to the list gets notified.
John (A cranky old man. "Looking for an echo ...")
using any control-panel install/update is like shooting yourself in the foot. It won't kill you, but you're really going to hobble around until it heals.
Using the wrong tools (Front Page, DreamWeaver) gives the same results
Do not PM me for Support!

Myztri
Registered User
Posts: 14
Joined: Tue Sep 21, 2004 8:25 pm
Location: Texas
Contact:

Post by Myztri »

I will be th first to admit that i got hacked for my failure t update and upgrade.

By_Korsan
Registered User
Posts: 3
Joined: Mon Oct 17, 2005 6:46 pm
Contact:

forum

Post by By_Korsan »

ne varmı su an nette

massimomassimo
Registered User
Posts: 15
Joined: Sat Oct 11, 2003 7:51 pm

Post by massimomassimo »

ok, firstly thanks everyone for all your help. I have tried all this but i cant maintain all my old posts etc and i still get the hack when i reinstall and re upload the config file. is there any way to upload it all and get rid of this hacK?

massimomassimo
Registered User
Posts: 15
Joined: Sat Oct 11, 2003 7:51 pm

Post by massimomassimo »

ok, i basically reinstalled the forum, and now i have it all back up with my template, but just without all the posts and memberlists, so was just wondering how to get that back up without bringing the hack back up? i reuploaded my config file but that hasnt changed anything.... which files should i re upload? should the config file be making a difference?

User avatar
Lumpy Burgertushie
Registered User
Posts: 67733
Joined: Mon May 02, 2005 3:11 am
Contact:

Post by Lumpy Burgertushie »

massimomassimo wrote: ok, i basically reinstalled the forum, and now i have it all back up with my template, but just without all the posts and memberlists, so was just wondering how to get that back up without bringing the hack back up? i reuploaded my config file but that hasnt changed anything.... which files should i re upload? should the config file be making a difference?

the problem is that the hack is in your database, everytime you restore it, you get the hack back

go into the database and clean out the hacker stuff. it is usually in the forum descriptions or server name fields, check every single table and field for any html or javascript or anything else that is not supposed to be there,

also, check the phpbb folder for any files that are not part of phpbb, etc.

robert
I'm baaaaaccckkkk. still doing work on donation basis. PM your needs.

Premium phpBB 3.3 Styles by PlanetStyles.net

If nobody is in the forest, does a tree really fall?

Locked

Return to “2.0.x Support Forum”