Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
March 15, 2010, 06:38:27 AM

Pages: [1]   Go Down
  Print  
Author Topic: Securty issues  (Read 1232 times)
frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« on: September 12, 2009, 04:33:19 AM »

Received a email from Lunar saying this
Hello, During a recent security scan on your server, we found the following script on your account: User: makin21 System: oceanus Viewscan found the following security issues: Script: /home/makin21/public_html/notes.php Reason: r57 shell viewer Script is disabled and renamed to Script: /home/makin21/public_html/notes.php_contact.support Please update all scripts and plugins and remove the files which you haven't uploaded, within 24 hours. Please also update all your passwords. Please don't ignore this mail else we have to suspend your account as per company policy.

then I contacted them letting them know I do not install or know how to install or fix anything in the backside and the person that did my site is out of country at time.
They then told me this
Hello, Based on the message that you received, it would indicate that the file listed may have a "shell viewer" written into it. You will need to review the file, and see if it has script in it you did not put in, or if the file is not needed for your script, remove the file. It would also be recommended to insure that you are running the most recent version of your script, as running outdated scripts can lead to being compromised by 3rd parties. We are limited in the scripting, coding and support for third party applications that we can provide through the help desk, as the help desk is primarily for account and server issues. You may want to consult our community forums at http://lunarforums.com . There are many customers and lunarpages employees who frequent these forums answering questions and asking thier own. You would also have a wider audience to assist in answering your questions in the forums then you would through the help desk. Alternatively you may want to contact the provider of your script. Best regards, Troy Laclaire support@lunarpages.com

so can someone let me know what I can do to fix this>and do they mean every member should change their password or does it mean someone tried to hack my site> I am unclear
Logged
Mitch
Senior Moderator
Berserker Poster
*****
Online Online

Posts: 12696


Business Development Specialist at Lunarpages


WWW
« Reply #1 on: September 14, 2009, 06:01:00 AM »

I would suggest that you start with the steps I mention here:

http://www.lunarforums.com/lunarpages_security_center/i_think_my_site_is_hackedwhat_do_i_do-t53497.0.html;msg354508#msg354508
Logged

New Lunarpages Contest! - Win a Free Web Site Design! Enter Today!


Mitch the Moderator - follow me @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« Reply #2 on: September 15, 2009, 12:23:35 AM »

Mitch, Lunar has contacted me and let me know this
Hello, Based on the message that you received, it would indicate that the file listed may have a "shell viewer" written into it. You will need to review the file, and see if it has script in it you did not put in, or if the file is not needed for your script, remove the file. It would also be recommended to insure that you are running the most recent version of your script, as running outdated scripts can lead to being compromised by 3rd parties
Viewscan found the following security issues:

Script: /home/makin21/public_html/notes.php
Reason: r57 shell viewer
Script is disabled and renamed to Script: /home/makin21/public_html/notes.php_contact.support

Please update all scripts and plugins and remove the files which you haven't uploaded, within 24 hours. Please also update all your passwords.

But, problem I have is I know nothing about how to fix this as I dont write any Scripts. The person that does all my backside work is out of country and I cannot contact him. I dont know what else to do
Logged
Mitch
Senior Moderator
Berserker Poster
*****
Online Online

Posts: 12696


Business Development Specialist at Lunarpages


WWW
« Reply #3 on: September 15, 2009, 05:03:23 AM »

Did you follow the advice in the previously linked to thread?  Along with that, I would suggest that you remove the files they make note of in your reply.  Let us know what you have done, as well as keep working with the server admins to get this fixed, and we'd be happy to help suggest ideas and fixes to you here via the forums.
Logged

New Lunarpages Contest! - Win a Free Web Site Design! Enter Today!


Mitch the Moderator - follow me @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« Reply #4 on: September 15, 2009, 05:23:12 AM »

Did you follow the advice in the previously linked to thread?  Along with that, I would suggest that you remove the files they make note of in your reply.  Let us know what you have done, as well as keep working with the server admins to get this fixed, and we'd be happy to help suggest ideas and fixes to you here via the forums.
I would love to remove the things but I dont even know where to find them. I will have to hire someone. Not sure where I post to hire them
Logged
wektech
Jedi
*****
Offline Offline

Posts: 920



WWW
« Reply #5 on: September 15, 2009, 10:58:30 AM »

Your site seems to be a phpbb site. I suspect the notes.php is part of a mod that has been enabled for the site. I believe the mod probably allows the users to save personal notes in the database. You should be able to verify this by seeing if the mod has quit functioning.
Logged

frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« Reply #6 on: September 15, 2009, 11:03:37 AM »

Your site seems to be a phpbb site. I suspect the notes.php is part of a mod that has been enabled for the site. I believe the mod probably allows the users to save personal notes in the database. You should be able to verify this by seeing if the mod has quit functioning.

that is the problem, I dont know anything about installing or anything to do with mods?
I am waiting for Lunar pages to contact me back but its been a week.
Logged
wektech
Jedi
*****
Offline Offline

Posts: 920



WWW
« Reply #7 on: September 15, 2009, 11:37:44 AM »

LP does not do any support for user scripts, so I would not expect much help from them. After looking over your site, I suspect that the mod is disabled or possibly only enabled for moderators and administrators. If no users or moderators are complaining about loss of functionality, perhaps you should just delete the file that was renamed to notes.php_contact.support and wait for your backside work guy to return.
Logged

frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« Reply #8 on: September 15, 2009, 12:57:36 PM »

My problem is I dont know even how to find that script or what its for.
Can you give me a walk through? I have added and removed things from the Overall Header before so am familiar with backside. I am the only Admin and have no moderators
Logged
wektech
Jedi
*****
Offline Offline

Posts: 920



WWW
« Reply #9 on: September 15, 2009, 02:04:33 PM »

Probably the easiest way to do this is to use the file manager in Cpanel. Once you have opened file manager click the icon next to public_html which should show you all the files in the public_html folder/directory. scroll down till you find the notes.php_contact.support file and click the icon next to it. look in the upper right hand corner of the screen and you should see the file name with a list of option under it including the delete file option. Clicking that link should delete the file from the public_html directory. Actually it moves it to a directory called trash in the root folder for your account, where it can be recovered (as long as you do not empty the trash) if you find that you need it.
Logged

frankie
Intergalactic Cowboy
*****
Offline Offline

Posts: 67


« Reply #10 on: September 15, 2009, 02:24:43 PM »

whew now that was simple and I followed it and sure enough Lunar Support was on phone as I did it lol
So he was pleased that you were kind enough to help me out. Thank you so much
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: