Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

php website hacked - advice needed

Options
  • 02-07-2011 10:31pm
    #1
    Registered Users Posts: 108 ✭✭


    Hi a friend of mine runs a forum and it has been hacked
    he wants to try and get it repaired and determine who done it
    can anybody on here tell me
    1. where can he get someone who really knows there stuff to fix it at a affordable price and
    2 . can the person who did it be determined

    any help at all would be greatly appreciated

    i hope i have posted this in the right place :confused:
    Thanks


Comments

  • Registered Users Posts: 10,992 ✭✭✭✭partyatmygaff


    Was it a phpBB forum or something that was hacked? How bad was the attack in terms of damage? As for determining the person who carried out the attack, that depends on how skilled the person who orchestrated the attack is in cloaking their identity.


  • Registered Users Posts: 108 ✭✭mr c


    sorry im not really sure
    it is a forum using
    simple machines smf
    i dont really know anything about this kind off stuff :o


  • Registered Users Posts: 3,140 ✭✭✭ocallagh


    First thing I would do is contact your hosting company. A lot of the time they will sort this out for you by restoring a previous backup of the file system and also the database.

    If they can't help out you'll need a web developer with experience in PHP/MySql and preferably forums/SMF to fix it. Two things they'll need to do:
    1. Wipe file system and fresh install of SMF
    2. Check if the database was compromised (probably was). If so, you'll need to restore a previous backup.

    Once you have your system back up and running you'll need to reset all your passwords and will definitely need to hire a developer/sysadmin with experience in security to find out how the hacker got in and make sure it doesn't happen again.

    To find out who orchestrated the attack will more than likely be an expensive & fruitless exercise.

    You should contact all members and let them know their passwords may be compromised.


  • Registered Users Posts: 108 ✭✭mr c


    thanks for the advice i will tell my friend
    cheers


  • Registered Users Posts: 2,781 ✭✭✭amen


    You should contact all members and let them know their passwords may be compromised.
    and of course you are registered with the data protection commissioner and will be informing them of the breach


  • Advertisement
  • Registered Users Posts: 10,992 ✭✭✭✭partyatmygaff


    amen wrote: »
    and of course you are registered with the data protection commissioner and will be informing them of the breach
    Not-for-profit organisations are not obliged to register with the data protection commissioner.


  • Closed Accounts Posts: 20,759 ✭✭✭✭dlofnep


    Firstly - You can minmise these problems by making sure that the forum software is always up to date. If you even miss an update by 1 day, you are at risk of being compromised. It is the responsibility of whoever runs the forum to make sure it's up to date.

    As for tracking down who did it - it's possible, if they did not use a proxy. Chances are there was some form of SQL Injection involved - So what I would do if I was the admin is browse over the access_logs of the forum and start grepping for typical SQL injection strings such as "union select".

    If you don't understand SQL Injection, then don't bother. You need to understand how the attack works before you understand who's responsible.


  • Registered Users Posts: 2,781 ✭✭✭amen




Advertisement