PDA

View Full Version : I have been hacked. Help Please.


annemy
09-10-2008, 01:45 AM
Hello,
I have been hacked a few times in the past, and have been able to fix the issues, but this time I am stumped.
It seems my website is still complete, from what I can tell in cpanel, but it seems that when I type in my website name, it is being redirected to another website.
I have been through all my files, and see nothing out of sorts. Can any website savvy people tell me how someone is able to do this? but more importantly how do I fix it?
If I found a newly added file, or some sort of reference to the site it is being redirected to, I could fix it, but I cant find anything. This is so frustrating.
I am not allowed to post the url to my site, but it is adult-hotlinks dot com and it is now being redirected to a religious site.
Any help would be greatly appreciated.

James
09-10-2008, 02:17 AM
first of all ftp in and edit the the tpl files that were changed with the javascript redirect most likely header.tpl .....


Other than that ask hostdime what happened.....

10 to 1 you either have another script that is exploitable or something similar.

Upgrade to 3.x

and purchase a removal license for adult use even if 2.x

annemy
09-10-2008, 02:58 AM
first of all ftp in and edit the the tpl files that were changed with the javascript redirect most likely header.tpl .....


Other than that ask hostdime what happened.....

10 to 1 you either have another script that is exploitable or something similar.

Upgrade to 3.x

and purchase a removal license for adult use even if 2.x

Thank you for your suggestion. I have searched the files, but I am not too savvy with php nor javascript. The thing is I am not sure which file has been changed. I looked at all my .tpl files, and compared them to my other php link directory, and I cant see any differences. I am at a loss. If I reload the whole site, (which I am really reluctant to do) would that solve it?...I am thinking not.

I also looked up whois, to see who the owner of the website that has hijacked my website is, and found thier details, but also out of curiosity I looked up my own, whois information for my website, and it is now someone elses details. All my other websites still have my details. How can they actually change the whois information for the site, or is it just reflecting the redirected sites details...a bit off topic, I know, but am curious.

Also, I am quite happy to pay for the removal licence, if that helps my website, but am curious why you are suggesting it. Could you please explain? I am using the free version at the moment, and am looking at upgrading to 3.x, but would like to know that the script is secure first. As I am sure you would understand, I would be reluctant to pay for a script if it is keeps getting hijacked. I will be password protecting my files and folders once I sort this mess out. I am hoping that will help.

thanks again, for your help

James
09-10-2008, 04:54 PM
IN regards to the license we ask that ALL adult related sites purchase the unbranded version of the scripts .. Not a demand but we do appreciated it very much :)