Blog Hacked

Random stuff about serendipity. Discussion, Questions, Paraphernalia.
Post Reply
basshook
Regular
Posts: 13
Joined: Sat Jan 22, 2011 5:55 am

Blog Hacked

Post by basshook »

Just visited my blog after not being to it since mid April and see that it was hacked somehow. Using version 1.5.5. When I tried to go to my blog page I got sent to the installation page (see below) so I am assuming the hacker didn't really get it right whatever he/she was trying to do. When I checked my database I'm seeing links to .ru among others inside my serendipity_referrers, serendipity_refs, serendipity_suppress database tables so I've deleted all the files from my server. I want to install the 1.6.2 version and was wondering if I could just upload the existing database after removing all the bad data to the new version or should I just copy over my posts? Hopefully I won't have to start over. Is the bullet proof theme compatible with version 1.6.2? I've modified mine quite a bit.

Image
Last edited by basshook on Mon May 21, 2012 2:20 am, edited 1 time in total.
yellowled
Regular
Posts: 7111
Joined: Fri Jan 13, 2006 11:46 am
Location: Eutin, Germany
Contact:

Re: Blog Hacked

Post by yellowled »

basshook wrote:JIs the bullet proof theme compatible with version 1.6.2? I've modified mine quite a bit.
I can't really give an informed opinion on the rest of it, but yes, Bulletproof works just fine with 1.6.2.

YL
basshook
Regular
Posts: 13
Joined: Sat Jan 22, 2011 5:55 am

Re: Blog Hacked

Post by basshook »

Thanks Yellowled, I installed a fresh version of 1.6.2 and just copied over my upload files/folders, template changes, and added all my comment/post/category/image data to the new database and everything seems to be working fine. Whew... :D
garvinhicking
Core Developer
Posts: 30022
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: Blog Hacked

Post by garvinhicking »

Hi!

This sort of hacking more seems to me like a FTP-account hijacking, rather than a targeted s9y exploit.

You should definitely reset your FTP password, if you didn't already do so, and do a trojan/virus scan on all computers that you used the FTP access on.

Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/
basshook
Regular
Posts: 13
Joined: Sat Jan 22, 2011 5:55 am

Re: Blog Hacked

Post by basshook »

Thanks Garvin, changed the password but the scan found nothing on the computer that I use.
Post Reply