leewalesuk Posted June 5, 2012 Share Posted June 5, 2012 Hi everyone I am new to this site so hope i have posted this in the right place. I have a Phpfox website but have been attacked by a remote file inclusion. my host has disabled the mysite/static/ajax.php and the files that the hacker installed on my server. now that the file is disabled quite a bit of my site does not work e.g. notifications,feedback,messages etc Was wondering if anyone could explain how to secure this from attack as file permission is set to 200 to stop the attack but i need to set the right file permission on this file to get my site working correctly. But i cant just set to 644 as the attack will continue and i will have my hosts abuse department on my case again. Any help with this issue would be appreciated as i really need my site working correctly again. thanks lee Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/ Share on other sites More sharing options...
ignace Posted June 6, 2012 Share Posted June 6, 2012 Head on over to the phpfox website and contact their support. If there is an exploit in their software you must be able to download a patch. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1351578 Share on other sites More sharing options...
smoseley Posted June 6, 2012 Share Posted June 6, 2012 When you say "right file permission", do you mean "777"? Cause that is not right, and would explain the hack. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1351612 Share on other sites More sharing options...
Jessica Posted June 6, 2012 Share Posted June 6, 2012 The op did say 644, not 777. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1351673 Share on other sites More sharing options...
leewalesuk Posted June 6, 2012 Author Share Posted June 6, 2012 Hi ive been there and have the latest updated software. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1351753 Share on other sites More sharing options...
ignace Posted June 7, 2012 Share Posted June 7, 2012 Then report they have an RFI issue they need to resolve. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1351819 Share on other sites More sharing options...
leewalesuk Posted June 9, 2012 Author Share Posted June 9, 2012 Hi everyone i found the problem, it was my ipb board script, i updated the script with new version, then removed 4 rogue files from server now site is back working correctly. Quote Link to comment https://forums.phpfreaks.com/topic/263730-phpfox-site-attacked-by-rfi/#findComment-1352528 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.