|
|||
|
First thing to do is locate the mal CODE that is doing this
second is to write a simple php script or something to do a search and replace on all .htm files str_replace() will be of use Also, you say 'hacked'... I would call this some one having an account on your server, and takin advantage of the OPEN_BASE security issue you have yet to address, thus giving him access to every file and folder on your server... He could actually do a lot more than change HTM files, so think your self as lucky
Last edited by jaymc; 12-01-2005 at 09:31 AM. |
|
|||
|
I had this in my server as well it was a file called flame.php that was loaded in a users images folder. when this path was called it redirected all the sites to a forign server(meaning not mine).
When i suspended this site it then redirected all my sites to teh suspend page untill i rebooted teh server. I also noticed that if you change the password for this domain or account on teh server they can still get access to it so you want to suspend the site if you can find teh files and then delete the files then change teh passowrd. |
|
||||
|
Quote:
__________________
Andy Reed ServerTune.com Dedicated server hosting, Colocation Services, Server Management, and cPanel Licenses |
|
||||
|
He can if you wishes to. Any has a good reputation on these forums for helping people in such situations, as have others.
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
![]() |
| Thread Tools | |
| Display Modes | |
|
|