ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Parse error: syntax error, unexpected T_STRING

November 12, 2009 10:50pm

Subscribe [8]
  • #16 / Nov 23, 2009 5:59pm

    Ingmar

    29245 posts

    http://kb.mediatemple.net/questions/1715/Working+with+a+php+injected+website

    From what we know so far, this is not a case of PHP injection. I seem to remember that MT admitted that the attacks were carried out via regular FTP. Either way, let us know if there are new developments, please.

  • #17 / Nov 23, 2009 6:05pm

    justjess

    16 posts

    Hi Ingmar,

    I’m struggling to understand how so many people using secure passwords could have ftp password violations at the same time without some sort of breach. Am I just really naive, or does this strike you as unlikely as well?

  • #18 / Nov 23, 2009 6:10pm

    Ingmar

    29245 posts

    It might very well be a hosting issue of some sort, but only MT would be able to tell you about it. It certainly does not look like an EE issue at this point, if only for the fact that these incidents seem to be limited to MT, and do affect all index.php files (actually breaking EE in the process, making it easy to spot.)

  • #19 / Nov 23, 2009 6:15pm

    justjess

    16 posts

    I do not believe it to be an EE issue - code has been added to every index file (php/html) on every domain hosted on my server. As well as htaccess rewrite spam. EE sites are simply the only ones that break right away. MT has an uphill battle convincing me that this is due to my ftp password being unsecure.

  • #20 / Nov 23, 2009 6:21pm

    Ingmar

    29245 posts

    MT has an uphill battle convincing me that this is due to my ftp password being unsecure.

    Yes, I think you’ve got a point there. I probably wouldn’t be entirely convinced, either.

  • #21 / Nov 23, 2009 7:25pm

    Minakami_Mike

    4 posts

    The same “hack” has just happened to me again!  I have now changed my passwords for FTP and will see if that makes a difference.

  • #22 / Nov 23, 2009 7:46pm

    Adam Dorsey

    1439 posts

    Please let us know. Again, we take security seriously. Thanks for all of your hard work reporting this!

  • #23 / Nov 24, 2009 5:58am

    kev_horan

    50 posts

    Hi there,

    I’ve included the MT response here - it doesnt address what happened, and tells me to do what Id already done. The attacks affect any index & htaccess file - regardless of whether theres a CMS installed or which CMS it is.

    Thanks for contacting us regarding this issue. It appears that your service was compromised as code had been injected into many parts of your account. Our engineers noticed an influx of IP addresses on the internet attempting to access your server, so we changed your Server Administrator password as a security precaution. We would recommend at this point that you consider auditing your code to make sure there have not been any changes made to it that you did not authorize. I’ve had an engineer scan and remove any malicious code or content from your scripts.

    If you find anything else in your files, we recommend that you immediately remove the offending code, and do an audit of any software you might have installed (along with any plugins for that software) to make sure you are running the most current version. I’ve provided a link to our KnowledgeBase article on things to check for: http://kb.mediatemple.net/questions/1715/

    If you have any other questions, or need further clarification, please let us know.

  • #24 / Nov 24, 2009 9:05am

    Sue Crocker

    26054 posts

    Thanks for the feedback on what MT said, kev_horan.

    Don’t hesitate to post again as needed.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases