Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2006-01-04 11:43:29

Skubidu
Archived Plugin Author
Registered: 2004-10-23
Posts: 611
Website

My website was hacked...

Hello everybody!

Last night my website has been hacked and I don’t know yet how this could happen. So I’m not sure if it is a problem caused by textpattern. I’m using 3 scripts on my page:

  • Textpattern on root level
  • Mint in a subfolder
  • Plogger in a subfolder

All scripts have be up-to-date (as far as I know). I could restore the website quickly because it was just textpattern’s index.php that has been overwritten. Is there any known but not yet published security issue in the textpattern code that could have caused this problem?

Hope, no one else is having such problems!

Nils

Offline

#2 2006-01-04 11:55:40

Jeremie
Member
From: Provence, France
Registered: 2004-08-11
Posts: 1,578
Website

Re: My website was hacked...

You should look at your server (Apache) logs, to see what was called, from where, how, and so on at the moment of the attack. It might help you (and/or the dev of those apps) to figure it out. By the way, it’s doesn’t have to be a failure of one of these app. Could be a failure at several others checkpoints.

Offline

#3 2006-01-04 11:58:19

Skubidu
Archived Plugin Author
Registered: 2004-10-23
Posts: 611
Website

Re: My website was hacked...

<blockquote>By the way, it’s doesn’t have to be a failure of one of these app. Could be a failure at several others checkpoints.</blockquote>

I know. I contacted my host concerning this problem…

Offline

#4 2006-01-04 12:55:07

Skubidu
Archived Plugin Author
Registered: 2004-10-23
Posts: 611
Website

Re: My website was hacked...

Okay – so I got feedback from my hoster: The problem wasn’t caused by textpattern. It was a plogger problem…

Offline

#5 2006-01-04 13:19:56

hcgtv
Plugin Author
From: Key Largo, Florida
Registered: 2005-11-29
Posts: 2,722
Website

Re: My website was hacked...

Plogger is still in beta, I would run it locally for testing purposes but never on a production site.

Is this Mint? -> http://www.haveamint.com/

Offline

#6 2006-01-04 13:29:45

Skubidu
Archived Plugin Author
Registered: 2004-10-23
Posts: 611
Website

Re: My website was hacked...

@hcgtv:

You’re right that one should not run betas on a live site. Well, but if I had waited for textpatterns final release back then, I would have become very, very old ;) But yes, you’re right.

And a second yes: Mint is the Mint.

But as I said: The problem wasn’t caused neither by textpattern nor by Mint.

Offline

#7 2006-01-04 14:20:34

hcgtv
Plugin Author
From: Key Largo, Florida
Registered: 2005-11-29
Posts: 2,722
Website

Re: My website was hacked...

I’ve been playing with Plogger locally, I like what I see, it would make a nice gallery to compliment Textpattern for sure.

Textpattern did take a while to come out of beta and then one day I see version 4 is released, I thought I had missed several release cycles.

As for a simple and stable gallery, I use singapore myself.

Offline

Board footer

Powered by FluxBB