ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Expression Engine 1 client site hacked

October 30, 2012 12:24pm

Subscribe [2]
  • #1 / Oct 30, 2012 12:24pm

    Hi there,

    I’m working for my client over at http://beyondthestreets.org.uk/ and recently got an email from them saying they were notified of the following link (safe but dont click any of the links on the page) Hacked Site Link.

    I’m guessing they someone managed to access the database, given the nature of the entries. I’m going to upgrade the site to use expression engine 2 but want to deal with this first. Any ideas were this content might be located?

    If you need any other information let me know.

    Thanks, in advance.

  • #2 / Oct 31, 2012 3:34pm

    Shane Eckert's avatar

    Shane Eckert

    7174 posts

    Hey there Mark,

    I am sorry to hear you are running into this problem. Getting hacked is no fun.

    I want you to know that we take security very seriously and will do our best to work with you on figuring out what’s going on.

    Please call your hosting provider and let them know you are being hacked. They need to know this in order to help stop it. Typically the only way to get rid of this is to find out how the exploit is being made and to repair that.

    This could be an operating system level fix or it could be another application installed in your web root. Do you have anything else installed, like phpBB, WordPress, or the like?

    It’s probable that these files are corrupted as well.

    
index.php

    admin.php

    system/index.php

    system/expressionengine/config/config.php

    Search the above files to ensure that there is no unusual code such as iFrames or Javascript includes; if you do find that code, then please back-up the file and remove said code.  If you are unsure of what does or doesn’t belong in these files, do not hesitate to ask.

    You may also wish to refresh your files by following the update instructions.

    Sorry to repeat myself, but I want to make sure this point comes across. You will be fighting a losing battle until you get rid of the exploit. Make sure no other apps are installed and if they are, list them here.

    If you are not using them, delete them. And please be sure to let you hosting service know. You might not be the only one with this frustration.

    Again, I am sorry you are dealing with this.

    Please keep me posted!

    Cheers,

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases