Jump to content

Recommended Posts

Posted (edited)

My Invision Power Board has been hacked, what to do ?

 

[Link removed due to objectionable content.]

Edited by Rickvz
Posted

Thanks for restoring my board Rick, what is the best way to prevent this from happening again ?

Posted

Thanks a lot, you played a blinder mate.

 

The support at TCH is 2nd to none, I love this place.

Posted

Rick

 

How is that possible for someone to gain access to that, install.php file on the sever?

 

Is there any preventive action that someone can take to prevent that from happening in the future?

 

Richard

Posted

The install.php file is supposed to be deleted once you finish the install of the forums. It's easy to gain access to it if you know the path to the root forums folder.

 

For example, if I install an Invision board to www.mysite.com/forum the root folder for the board is /forum. When you install an IPB one of the steps is to navigate to www.mysite.com/forum/install.php this sets up everything for your message board, including admin username and password. If you dont delete that file, anyone can navigate to it and change whatever they want.

 

Another file you want to make sure is secure is config_global.php. This file has your database name as well as the database username and password in it, you dont want anyone accessing it and changing up your info

Posted

Mike,

 

A simple, probably naive, question:

 

You say that config_global.php should be "secure". I am assuming you mean that permissions need to be set a certain way. What should they be for the board to work, but still safe?

 

...Dave Rock Sign

Posted

Mike

 

Good info, thanks.

 

Should that install.php file be download for future use, before deleting it or is it not needed any longer?

 

Any suggestions on making that config_global.php file secure?

 

 

Richard

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...