My site was hacked by someone doing a phishing scam. Here is the code my service provided sent me. ........................................................................................................................................ It seems some files on your site are vulnerable to hack attempts. Every minute you get atleast 5 hack attempts being made to your site. Here is a sample of the hack attempts:-
Is there a fix for this? I don't have a clue on how to correct this. My service provider is setting me up on another server so I can do a fresh install, but I want to make sure I set it up without being vulnerable to this or any other type of hacking.
Admittedly, I never gave much thought to security or being hacked. The old "It can't happen to me" mentality. Lesson learned the hard way.
It goes without saying, your help with this issue will be greatly appreciated.
What else do you have installed on your machine? Those really don't look like Plogger URL's. Based on the HTTP requests above, I would venture to say that this may have nothing to do with Plogger.
The reason I say it is not Plogger is because none of the variable names in the URL exist in Plogger. $_Request[Itemid], this is not used in Plogger. mosConfig_absolutepath, nowhere to be found. Setting these variables through this "vulnerability" (hint: turn off REGISTER_GLOBALS) would have no effect on any Plogger installation.
What's up with the file pathname "/mambo/index2.php"? Do you have a folder called mambo on your hosting account?
No. However I did have an index2.php when I was customizing the home page and wanted to have the original index file available just in case I screwed something up. The mambo part is a mystery to me.
I just deleted the gallery and everything else I could on the original server so there is nothing to check there at this point. I hope this won't affect your ability to figure this out.
If Plogger itself could not be hacked in this way, would you have any idea where the security gap could be?
I think this is a random attempt to hack a Mambo site that is not there... So Plogger should be safe enough from this. But such random attacks can put a big strain on a server and is a royal pain in .. yeah.. :-)
I think you're right. There were phishing files in my directory that I could not delete which suggests the hack was at the server root. Thanks for your input.