Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > SUPPORT / INFORMATION > Pixelpost Help

Post Reply
 
Thread Tools
  #1  
Old 04-22-2007, 05:59 PM
mark Offline
pp veteran
 
Join Date: Feb 2005
Location: Atlanta, GA USA
Posts: 89
Someones hacking my pixelpost database

Any ideas how to stop a hacker from writing HTML code to my pixelpost database? Someone is writing some <iframe> stuff to categories and my pixelpost config making it point people to a trojan virus. thoughts??

-mark
Reply With Quote
  #2  
Old 04-22-2007, 06:02 PM
jaywilliams's Avatar
jaywilliams+ Offline
Team Pixelpost
 
Join Date: Sep 2005
Posts: 1,003
Send a message via AIM to jaywilliams Send a message via MSN to jaywilliams Send a message via Yahoo to jaywilliams Send a message via Skype™ to jaywilliams
For starters, change your database password.

Then update your pixelpost.php file to reflect the changes.
__________________
Jay Williams | A Different View
Reply With Quote
  #3  
Old 04-22-2007, 06:04 PM
mark Offline
pp veteran
 
Join Date: Feb 2005
Location: Atlanta, GA USA
Posts: 89
I've done that, but i assume they already got my password by reading my pixelpost.php file...
Reply With Quote
  #4  
Old 04-22-2007, 07:17 PM
blinking8s's Avatar
blinking8s+ Offline
über loafer
 
Join Date: Oct 2004
Location: Bowling Green, Ky
Posts: 3,428
Send a message via ICQ to blinking8s Send a message via AIM to blinking8s Send a message via MSN to blinking8s Send a message via Skype™ to blinking8s
what pixelpost version are you using?
__________________
i should say more clever stuff
Reply With Quote
  #5  
Old 04-22-2007, 08:03 PM
mark Offline
pp veteran
 
Join Date: Feb 2005
Location: Atlanta, GA USA
Posts: 89
1.3...and yeah, i know i know.i should upgrade
But i have so much custom stuff in my index.php and admin section, im afraid to mess that up
Reply With Quote
  #6  
Old 04-22-2007, 08:57 PM
austriaka's Avatar
austriaka+ Offline
Team Pixelpost
 
Join Date: Nov 2006
Location: Germany
Posts: 1,175
Send a message via ICQ to austriaka Send a message via AIM to austriaka
better you messing it up then your hacker does...
;-)
KArin
__________________
Uh!log Photoblog
My Addons
Reply With Quote
  #7  
Old 04-22-2007, 11:47 PM
GeoS's Avatar
GeoS+ Offline
Team Pixelpost
 
Join Date: Apr 2005
Location: Warsaw, Poland
Posts: 3,613
Send a message via ICQ to GeoS Send a message via Skype™ to GeoS
First of all try to protect your admin dir by setting there controlled access through http loging option (many admin panels has got special function for making dirs secure accessed).
__________________
photoblog | portfolio | addons | Donate
Reply With Quote
  #8  
Old 04-23-2007, 12:36 PM
mark Offline
pp veteran
 
Join Date: Feb 2005
Location: Atlanta, GA USA
Posts: 89
I did setup permissions on my admin directory with a username and password via my hosting website control panel. I also changed my pixepost database password. It took the hackers a few hours to break through again and write html code ontop of my categories. Each time a photo shows that has a category, it also pops the virus....any thoughts to protect the database?
Reply With Quote
  #9  
Old 04-23-2007, 12:58 PM
austriaka's Avatar
austriaka+ Offline
Team Pixelpost
 
Join Date: Nov 2006
Location: Germany
Posts: 1,175
Send a message via ICQ to austriaka Send a message via AIM to austriaka
could it be that you have already some weird code in your scripts? Perhaps something so simple like the send-forgotten-password function misused (don't know the routine in 1.3, but perhaps one can perform the form with a replaced email adress?
I strongly believe it would be less work to make a complete new installation with 1.6 than to fix that issue
KArin
__________________
Uh!log Photoblog
My Addons
Reply With Quote
  #10  
Old 04-23-2007, 02:48 PM
mark Offline
pp veteran
 
Join Date: Feb 2005
Location: Atlanta, GA USA
Posts: 89
Where do i find the "forgot password" function?

And also, upgrading to 1.6 will fix the issue you think? 1.6 uses the same database tables doesn't it? Heck, if 1.6 will fix the issue, i'll definitely do that!
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 04:36 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs