Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2009-11-10 09:41:06

FireFusion
Member
Registered: 2005-05-10
Posts: 698

Malware attack - Can i just delete users?

I have a site using TXP 4.0.6 that google is reporting as having a Trojan on. Can I delete all the users in the TXP table via phpmyadmin to lockdown?

Offline

#2 2009-11-10 10:09:12

Gocom
Developer Emeritus
From: Helsinki, Finland
Registered: 2006-07-14
Posts: 4,533
Website

Re: Malware attack - Can i just delete users?

FireFusion wrote:

I have a site using TXP 4.0.6 that google is reporting as having a Trojan on. Can I delete all the users in the TXP table via phpmyadmin to lockdown?

You mean deny users from logging into TXP? Yes.

But that isn’t going to fix the cause. Or did some of your authors upload an infected file? If the infected file is there for a reason (not by upload accident), then you may want to verify your files and change all passwords.

Offline

#3 2009-11-10 10:16:37

Bloke
Developer
From: Leeds, UK
Registered: 2006-01-29
Posts: 11,454
Website GitHub

Re: Malware attack - Can i just delete users?

FireFusion wrote:

Can I delete all the users in the TXP table via phpmyadmin to lockdown?

Seems a bit drastic. I would backup the txp_user table and then set all user privs (bar your own) to 0 instead. At least then all the resources that have been uploaded will still have user logins attached to them so you can do some digging to see who uploaded what (if indeed something dodgy was uploaded via the TXP interface). If you need to delete user accounts you can always do it selectively later once you’ve found the culprit(s) and then reinstate the existing privs from the backup file. And then force all passwords to be reset too as Gocom suggests.

Last edited by Bloke (2009-11-10 10:19:30)


The smd plugin menagerie — for when you need one more gribble of power from Textpattern. Bleeding-edge code available on GitHub.

Txp Builders – finely-crafted code, design and Txp

Offline

#4 2009-11-10 10:31:26

FireFusion
Member
Registered: 2005-05-10
Posts: 698

Re: Malware attack - Can i just delete users?

I found the files. I suspect it was due to an FTP password leak rather then a TXP problem as the files where uploaded to the root. Am looking into it further.

Offline

Board footer

Powered by FluxBB