View Full Version : Hijacked Fauxtoblog!
fauxtog
04-20-2006, 06:27 AM
Suddenly, when I try to go to my admin page, I can't get in. Not only does my username and password not work, but when I try to use the "forgotten password" feature, it tells me that my user name does not match my email address. I'm completely locked out with no way that I know to get in.
Anyone?
http://fauxtoblog.com
Joe[y]
04-20-2006, 06:50 AM
there are no signs of it actually being hacked. have you checked the login details via your database? you take a tool like phpmyadmin to look inside the _config table and see what the email address listed is.
raminia
04-20-2006, 02:12 PM
visit this page for help on password recovery
http://www.raminia.com/ppwiki/index.php/PasswordRecovery
blinking8s
04-20-2006, 06:10 PM
see if you webhost updated anything as well...and post your server details...
fauxtog
04-21-2006, 06:53 AM
Well. I've been on location shooting all week, so I don't have too much time to mess with it, but I did browse the database in PHPadmin and it shows the correct user and email These don't work with "forgotten passoword." I'm not sure what it shouls show as the password, but it's a very long random number. I couldn't get any of the other above solutions to work, even the password_recovery.php.
raminia
04-21-2006, 07:23 AM
Well. I've been on location shooting all week, so I don't have too much time to mess with it, but I did browse the database in PHPadmin and it shows the correct user and email These don't work with "forgotten passoword." I'm not sure what it shouls show as the password, but it's a very long random number. I couldn't get any of the other above solutions to work, even the password_recovery.php.
if you still have problems contact me. I'll try to fix it for you. PM me or email me.
fauxtog
04-24-2006, 04:10 AM
I would love some help Raminia! I'm so busy with work and a baby coming any minute that the spam comments are getting out of control and I can't even get in to delete them. I'll send you my email address so we can do this off the forums, but we should eventually post what happened here.
raminia
04-26-2006, 06:17 AM
it's fixed. btw, you are using 1.4.1 or 1.4.3.... it's highly recommened to upgrade to 1.5RC1 asap because of security issues.
fauxtog
04-26-2006, 04:45 PM
Thanks Ramin. I know I need to upgrade, but for now I have the simple problem that because I couldn't get into my admin panel for a week or so, I have literally hundreds of spam comments. It may actually be thousands because I stopped clicking "older comments" about 50 pages in. So there are at the very least 500. Do I actually have to delete them one at a time? If so, I seriously would consider deleting the whole blog.
I just thought I'd click through some more pages of comments and got another 30 or so pages in before I gave up again, so I'm pretty confident that I have well over a thousand. Almost all of those pages of spam comments were left on the same day so I can only imagine the horror.
Any ideas?
Joe[y]
04-26-2006, 05:05 PM
Thanks Ramin. I know I need to upgrade, but for now I have the simple problem that because I couldn't get into my admin panel for a week or so, I have literally hundreds of spam comments. It may actually be thousands because I stopped clicking "older comments" about 50 pages in. So there are at the very least 500. Do I actually have to delete them one at a time? If so, I seriously would consider deleting the whole blog.
I just thought I'd click through some more pages of comments and got another 30 or so pages in before I gave up again, so I'm pretty confident that I have well over a thousand. Almost all of those pages of spam comments were left on the same day so I can only imagine the horror.
Any ideas?
in phpmyadmin you can delete a huge selection of rows. i'm not sure what the exact sql code would be but i'm sure theres a way to delete all rows with id's since wahtever id was your most recent since you got locked out. then upgrade to 1.5...
perhaps somebody else would know the correct sql code for this?
fauxtog
04-26-2006, 08:20 PM
Well. PHPadmin was the answer. I wish I knew to do it that way before. I just went to the comments and showed 100 rows at a time and looked carefully that I wasn't deleting any good comments within all the spam. All seems to be good, but I'll have to find some time to upgrade. Will it help with my spam much?
fauxtog
04-27-2006, 03:53 AM
Ah... I would have upgraded earlier if I would have read that mass deletion of comments was a feature in 1.5! Wonderful!!!
Thanks everyone. I'm glad I found the post about the new "preview" feature before I asked about it though. I was freaking out that I could see my future posts. :-)
Joe[y]
04-27-2006, 09:08 AM
Ah... I would have upgraded earlier if I would have read that mass deletion of comments was a feature in 1.5! Wonderful!!!
Thanks everyone. I'm glad I found the post about the new "preview" feature before I asked about it though. I was freaking out that I could see my future posts. :-)
haha - well, i think we forgot to mention that because it was a feature we added to the developer version so long ago that we kinda forgot it was new.
i'm glad you've got a temporary fix though. p.s. look in the addons section at the akismet addon - you'll find this useful.
vBulletin® v3.7.3, Copyright ©2000-2013, Jelsoft Enterprises Ltd.