Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - help
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

help

 Post Reply Post Reply Page  12>
Author
harun_k View Drop Down
Newbie
Newbie
Avatar

Joined: 25 February 2006
Location: Turkey
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote harun_k Quote  Post ReplyReply Direct Link To This Post Topic: help
    Posted: 09 May 2006 at 3:29pm

Miscellaneous  
Miscellaneous    
Add to favorites (estimated) 416 / 291 guests 142.9 %
I think someone is trying to hack my site I have changed the name and the place of my db but someone got into the forum as admin I have given the upload  permission to my members. stats given above makes me suspicious. what should I do? I have renamed the db  I have been using the version 8.0 RC1.1 And once I have entered my host panel and see many files are deleted but there is no ıp  I don't know.


Edited by harun_k - 09 May 2006 at 3:41pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 10 May 2006 at 8:59am
For maximum security don't use Access.

If you do have to use Access make sure the Access database is placed in a folder outside of your web sites public folders so that it can not be downloaded by a hacker.

If a hacker can download the Access database then you have no security over your forum being hacked.
Back to Top
harun_k View Drop Down
Newbie
Newbie
Avatar

Joined: 25 February 2006
Location: Turkey
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote harun_k Quote  Post ReplyReply Direct Link To This Post Posted: 10 May 2006 at 4:42pm
my host supports odbc can u explain how to use it
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 11 May 2006 at 10:13am
If you mean using a system DSN, then this is slower and un-supported by web wiz forums.

What you need to do is find if your host has a private database folder outside of the public folder for your site to place databases in.

All web hosts now adays have a folder like this for placing Access databases in so that they can not be downloaded by a hacker.

Contact your web host and findout where this folder is.
Back to Top
harun_k View Drop Down
Newbie
Newbie
Avatar

Joined: 25 February 2006
Location: Turkey
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote harun_k Quote  Post ReplyReply Direct Link To This Post Posted: 12 May 2006 at 4:37pm
Is there any way to delete a file on your web space without using host panel. I look at my space then I realise that some of my files were deleted for example default asp common asp and the others which are not in folders. what should I do to prevent this.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 13 May 2006 at 10:26am
The only way to be totally secure is get your web host to set read only permissions on all publicly viewable files within your web site.

Also make sure all passwords including forum admin, FTP, etc. are difficult to guess and contain letters and numbers.

If you think your site has been hacked then you should delete all files on your site and re-upload them, incase a hacker has placed a file on the server giving them back-door access to control your site and files.
Back to Top
harun_k View Drop Down
Newbie
Newbie
Avatar

Joined: 25 February 2006
Location: Turkey
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote harun_k Quote  Post ReplyReply Direct Link To This Post Posted: 13 May 2006 at 5:38pm
I give read only permissions for all files except db
 
you said :
a hacker has placed a file on the server giving them back-door access to control your site and files.
 
Are these files can find without deleting everything
I have checked if there is any file that I don't know but I couldn't find 
it's to difficult to reupload there are many files in uploads folder what is your suggestions about reuploading the site 
 


Edited by harun_k - 13 May 2006 at 5:43pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 15 May 2006 at 9:56am
They may have disguised the file using the same name as a file you already have for your site.

The only safe way is to completely delete all files on your site and upload original files again.
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.