Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


vBulletin, phpBB, & IPB Skins vBulletin Skins

Register
Register
Forum of the Month
vBulletin Setup
fotm

A vBulletin site devoted to helping webmaster optimize their search results in search engines.

Tag Cloud
Latest Threads
Forum Stats
7,500 Members
163,556 Posts
66 Users Online

Please welcome our newest member, gunnaracm!

Affiliates
Go Back AdminFusion » Management » Security and Legal Issues » Extremely Angry and Depressed
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 11-06-2006, 10:47 PM   #1

Rocket 442's Avatar

Title: Apprentice

Points: 4,057, Level: 18Points: 4,057, Level: 18Points: 4,057, Level: 18
Level up: 19%, 193 Points neededLevel up: 19%, 193 Points neededLevel up: 19%, 193 Points needed
Activity: 12%Activity: 12%Activity: 12%

Join Date: Jul 2006

Posts: 487

Location: Buffalo, NY

Rocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to behold

Recent Blog: Workload update
Send a message via AIM to Rocket 442 Send a message via MSN to Rocket 442  
 
Extremely Angry and Depressed

I'm not sure where to start here...

I had both of my forums pretty much deleted off of my hosts servers without full knowledge of one of them even being deleted.

Now... I konw some of you guys have 100x the members I do, and my forum isn't a money maker or anything, but like everyone else I've poured 2 years of my life into my main site.


So basiclaly, yesterday morning I wake up, go to check the forums and see in big bold letters
:Your Account has been suspended, please contact tech. support"

*DISCLAIMER: I am not good with databases, or even know the half of them, but I tried to keep up with them. What do you think about this:

(17:18:31) Rocket442Olds: hello, It says my account in suspended. Is this still from when something broke, or did I do something wrong?
(17:18:56) whisupport: yeah, it consumed 68% of the servers resources for over a 6 hour period
(17:19:19) whisupport: I've been struggling to keep the server up for the entire time before I could track the source
(17:19:29) Rocket442Olds: what is that from?
(17:19:30) whisupport: rebooted it 3 times
(17:19:34) whisupport: a php script
(17:19:58) whisupport: I'm going through the logs now trying to track the source, but the logs are huge so it takes some time to go through them
(17:20:24) whisupport: i just hope it isn't another spamming issue from a script
(17:20:29) Rocket442Olds: i havent edited anything myself, its all just my site which is joomla from the fantastico scrpit
(17:20:34) Rocket442Olds: and then smf forums
(17:20:41) Rocket442Olds: but i havent edited anything, and im all up to date
(17:20:42) whisupport: argh, it's probably the smf
(17:21:00) whisupport: I know that you are up to date, but the forums are hacked all the time
(17:21:32) whisupport: sorry, I fought it for nearly the entire day without success, so I had no choice but to suspend it so that other users can stay up
(17:21:41) Rocket442Olds: yeah, i understand
(17:21:48) Rocket442Olds: but i have no idea what is going on with it
(17:22:00) whisupport: stay online for me so that we can work together when I find it if you don't mind
(17:22:12) Rocket442Olds: okay, that is fine
(17:22:27) Rocket442Olds: one thing that i didnt do yet that i wanted to...
(17:22:35) whisupport: I'm bout tired of the forum scripts, I will say that...they are constantly a pain
(17:22:38) Rocket442Olds: i used domestic disturbance and built a forum with that
(17:22:40) whisupport: what?
(17:22:47) Rocket442Olds: for my other www.fbodyonline.com
(17:22:54) whisupport: pardon?
(17:22:54) Rocket442Olds: and havent deleted the old forum that i mocked up
(17:23:01) whisupport: ack
(17:23:18) whisupport: are you ready to remove it yet?
(17:23:21) Rocket442Olds: yes
(17:23:24) Rocket442Olds: i was going to this morning
(17:23:30) Rocket442Olds: i jsut had a critque for class yesterday
(17:23:32) Rocket442Olds: so i didnt have time to
(17:23:46) whisupport: let me turn the account back on and lets remove it and see if that is the culprit, that way I don't have to spend hours going through the log
(17:23:46) Rocket442Olds: its the /fbodyonline/ one
(17:23:52) Rocket442Olds: ok
(17:23:56) whisupport: give me a sec
(17:25:19) whisupport: okay, it's unsuspended and already attacking the server
(17:25:23) whisupport: hurry log in and remove it
(17:26:02) Rocket442Olds: is the quickest way through ftp?
(17:26:05) Rocket442Olds: thats the only way i knwo
(17:26:07) whisupport: no
(17:26:11) whisupport: through fantastico
(17:26:14) whisupport: inside your control panel
(17:26:18) whisupport: so that everything is removed
(17:26:26) whisupport: or else files will stay behind
(17:26:56) whisupport: the server load is up to 47%
(17:27:05) whisupport: normal is 0.42%
(17:27:19) whisupport: 63%
(17:27:34) Rocket442Olds: its not on fantastico
(17:27:38) Rocket442Olds: it was 1.1
(17:27:46) whisupport: I'm going to have to suspend the account
(17:27:52) whisupport: it's crashing the server
(17:28:05) Rocket442Olds: opk
(17:28:36) whisupport: what is the folder it is in?
(17:28:39) whisupport: the forum?
(17:28:49) Rocket442Olds: its the /fbodyonilne folder
(17:29:01) Rocket442Olds: fbodyonline*
(17:30:29) whisupport: is that all that is in that folder?
(17:30:40) Rocket442Olds: yes, its all just the smf forum
(17:31:21) whisupport: what is in fbodyonline1?
(17:31:36) Rocket442Olds: the add-on domain
(17:31:43) Rocket442Olds: with the forum, that wasnt the mockup one
(17:31:44) whisupport: any scripts?
(17:31:54) whisupport: is it the old forum?...not updated?
(17:32:12) Rocket442Olds: njope, they are both updatd
(17:32:26) Rocket442Olds: i just installed the fbodyonline1 on tues.
(17:32:35) Rocket442Olds: i just added the add-on domain then
(17:32:58) whisupport: okay I removed that folder and reactivated the account and that was not the problem
(17:33:37) Rocket442Olds: is it the real forum then, i have no idea
(17:33:38) whisupport: it is definitely a php script
(17:33:47) Rocket442Olds: well i have domesticdisturbance.us/smfforum
(17:33:52) Rocket442Olds: that is my main sites forum
(17:33:57) whisupport: I don't want to delete that
(17:34:05) Rocket442Olds: and then i have the fbodyonline one too
(17:34:05) whisupport: we need to be able to figure out what is wrong
(17:34:14) whisupport: I removed that folder entirely
(17:34:18) whisupport: so that was not the problem
(17:34:23) Rocket442Olds: sory, fbodyonline1*
(17:34:30) Rocket442Olds: but that is the add-on domain
(17:34:38) Rocket442Olds: it has to be one of those 2, i dont have anything else installed
(17:34:49) Rocket442Olds: i had a wordpress account, but deleted that through my fantastico about 3 weeks ago
(17:35:06) Rocket442Olds: but i'm gonna lose all my data when you dlete those right?>
(17:35:22) Rocket442Olds: because that would really suck
(17:35:29) Rocket442Olds: but i know we need to find the problem
(17:35:30) whisupport: that's what I don't want to do
(17:35:43) Rocket442Olds: im trying to think of anything it could be
(17:36:04) whisupport: tell me the names of the folders so that I can change their permissions and at least get your account back online
(17:36:04) Rocket442Olds: coudl it be joomla>?
(17:36:34) Rocket442Olds: okay: domesticdisturbance.us/joomla/ is the joomla main page of my site
(17:36:35) whisupport: I have no idea what kind of mods you have made to joomla. I have joomla installed in many accounts and do not have this problem
(17:36:46) whisupport: I'm referring to the forums
(17:36:50) Rocket442Olds: ok
(17:37:23) Rocket442Olds: fbodyonline1 folder is one smf forum
(17:37:24) whisupport: just give me the names of the folders that the forums are in so that I can change their permissions
(17:37:30) Rocket442Olds: and the /smfforum is the other
(17:39:49) whisupport: okay, it is definitely one of those forums. I unsuspended your account and immediately the server was attacked. I chmoded both forums to 000 and the attack stopped
(17:40:39) whisupport: are you there?
(17:40:54) Rocket442Olds: yes
(17:41:17) whisupport: give me a moment
(17:41:24) Rocket442Olds: ok
(17:42:47) whisupport: sorry
(17:42:56) whisupport: okay, so I'm not sure what to do from here.
(17:43:08) whisupport: are they identical forums?
(17:43:13) Rocket442Olds: nope
(17:43:21) Rocket442Olds: they are both smf, but didfferent in content
(17:43:33) whisupport: okay, I realize that lol...but as far as setups
(17:44:00) Rocket442Olds: they are the same smf version, and patches but the only difference is themese
(17:44:04) Rocket442Olds: themes*
(17:44:51) whisupport: that's not going to cause this
(17:45:27) Rocket442Olds: then they are basically the same
(17:45:38) Rocket442Olds: i have one mod on both of them
(17:45:42) Rocket442Olds: it just adds profile fields
(17:45:57) Rocket442Olds: but ive had it on the older forum (smfforum) for almost a year)
(17:46:26) whisupport: go to the smf forum and see if there has been a compromise
(17:48:10) Rocket442Olds: smf's site?
(17:48:13) Rocket442Olds: they dont have anyting
(17:48:16) Rocket442Olds: anything*
(17:48:38) whisupport: okay, I'm at a loss as to what to do
(17:48:57) Rocket442Olds: me too:-/
(17:49:08) Rocket442Olds: wnat me to post in their support and ask them?
(17:49:51) whisupport: no. if they kept up with things they would already have it posted. this has been going on since this morning
(17:50:02) whisupport: let me go through the server logs. this will take a few hours
(17:50:12) Rocket442Olds: okay
(17:50:19) Rocket442Olds: im really sorry, i didnt mean for it to happen
(17:50:26) Rocket442Olds: and i've stayed up to date
(17:50:39) whisupport: you can't control this
(17:51:02) whisupport: although you unfortunately take the blunt of the problem, I know that it is not your fault
(17:51:14) whisupport: but I can't let 300 people go down because of it
(17:51:34) Rocket442Olds: yeah, i understand that you have to cut my site off
(17:51:40) whisupport: no
(17:51:42) whisupport: your site is up
(17:51:46) whisupport: just the forums are down
(17:51:48) Rocket442Olds: my forums*
(17:51:50) Rocket442Olds: yeah
(17:51:51) whisupport: exactly
(17:52:24) whisupport: i'd rather your site be up and just your forums be down
(17:52:30) whisupport: so i'm glad that you came online
(17:52:38) Rocket442Olds: yeah
(17:52:52) Rocket442Olds: the main part of the site is the fourms, but its okay i understand fully
(17:53:05) Rocket442Olds: especially when other users will get hurt by the hosting too
(17:53:09) whisupport: okay, let me get to it. if you can keep you AIM online I'd appreciate it
(17:53:21) Rocket442Olds: i have to go to architecture studio for 2 hrs
(17:53:26) Rocket442Olds: but 'll be back by 8
(17:53:28) whisupport: if you can't, then just come online and message me once in a while
(17:53:34) whisupport: lol
(17:53:34) Rocket442Olds: okay, i can do that
(17:53:38) whisupport: thank you
(17:53:45) Rocket442Olds: bye, and good luck
(17:53:53) whisupport: thank you...I'll do my best
(17:54:10) whisupport: i own the servers and admin them...hopefully I'll see the problem
(18:12:46) Rocket442Olds: just checking in
(18:47:26) Rocket442Olds: any news
(18:47:34) whisupport: yeah
(18:47:45) whisupport: I've changed some permissions in your forums
(18:47:56) whisupport: I can't promise they will work, but so far so good
(18:48:08) whisupport: could you check your forums and see if they are working correctly?
(18:48:16) Rocket442Olds: yup, one moment
(18:48:52) Rocket442Olds: viewing and posting works
(18:49:13) whisupport: okay, well, I'll be watching it tonight
(18:49:27) whisupport: if something goes wrong with it again I'll suspend it
(18:49:31) whisupport: but so far so good
(18:49:33) Rocket442Olds: ok
(18:49:37) Rocket442Olds: do you konw what could have caused it?
(18:49:43) whisupport: nope
(18:49:49) whisupport: permissions are very touchy
(18:50:00) whisupport: I'm still going through the logs
(18:50:17) whisupport: I got tired of just sitting here watching for 1 entry in 2 million
(18:50:25) whisupport: so I took a chance and changed the permissions
(18:50:34) whisupport: and so far everything looks good
(18:51:19) Rocket442Olds: ok
(18:51:26) Rocket442Olds: well let me know if you find anything new
(18:51:39) whisupport: you are okay for now...just go have a rest..I'll be here for the night
(18:52:14) Rocket442Olds: ok, thanks
(18:52:28) whisupport: sorry for the bother
(18:53:14) Rocket442Olds: oh, i understand
(18:53:16) Rocket442Olds: sorry on my part too
(18:53:17) Rocket442Olds: lol
(18:53:30) whisupport: not your fault
(18:53:41) whisupport: have a good evening...I'll be here if you need me
(18:53:55) Rocket442Olds: okay thanks, i let membersk now if they see anything wierd to contact me

(19:36:40) Rocket442Olds: any updates?
(19:41:23) Rocket442Olds: the forums arent loading right now if you didnt know, not sure if you do or not
(19:44:55) whisupport: everything is the same on this end
(19:54:10) Rocket442Olds: hmm wierd
(19:54:14) Rocket442Olds: both forums arent loading
(19:54:17) Rocket442Olds: its just leaving a blank page
(20:15:56) Rocket442Olds: maybe the permissions mixed something up, im not sure
(21:34:45) Rocket442Olds: not trying to bug you, just wondering if you've found anything out, either about the problem or why the forums aren't showing up.

(00:21:14) Rocket442Olds: you there?
(00:36:15) Rocket442Olds: if you can, update me when you have time, thanks

(08:10:30) whisupport: Please check your forums now and let me know
(08:10:30) Rocket442Olds <AUTO-REPLY>: Sleeping
(09:39:25) Rocket442Olds: viewing them works, I get this error when attempting to post
(09:39:27) Rocket442Olds: Got error 127 from storage engine
File: /home/olds442/public_html/fbodyonline1/Sources/Subs-Post.php
Line: 1564
(09:40:04) Rocket442Olds: Database Error: Can't open file: 'smf_log_activity.MYI' (errno: 145)
File: /home/olds442/public_html/smfforum/Sources/BoardIndex.php
Line: 363
(09:40:31) whisupport: hmmm
(09:40:56) Rocket442Olds: now its giving me that error even trying to view them, not just post
(09:41:11) whisupport: give me the url
(09:41:35) Rocket442Olds: http://www.fbodyonline.com/
(09:41:43) Rocket442Olds: http://www.domesticdisturbance.us/smfforum/index.php
(09:43:51) whisupport: lord
(09:44:13) whisupport: there is something very wrong here. you are taking up over 2 gigs with your databases
(09:44:18) whisupport: no wonder they are not working
(09:44:28) whisupport: you only have a 300mb account plan
(09:46:09) Rocket442Olds: the sql databases
(09:46:10) Rocket442Olds: ?
(09:46:14) whisupport: yeah
(09:46:20) whisupport: log into your control panel and look at the size
(09:46:27) Rocket442Olds: it says on my cpanel i hae 2606.61 mb left
(09:46:35) whisupport: no it does not
(09:46:40) whisupport: that's how much you are using
(09:47:00) Rocket442Olds: Disk Space Usage 276.57 Mb MySQL Disk Space 2607.61 Mb
(09:47:06) whisupport: exactly
(09:47:20) whisupport: you are using 2607 with just mysql
(09:47:59) whisupport: because mysql databases are stored outside of your account the disk space can not be calculated together, so it shows you how much you are using instead
(09:48:07) Rocket442Olds: oh
(09:48:19) whisupport: it's this way on all cpanel servers
(09:48:44) whisupport: what is the password you use to access your control panel?
(09:48:51) Rocket442Olds:********
(09:50:59) whisupport: now the mysql disk space is up to 3348
(09:51:06) whisupport: are you doing something?
(09:51:45) Rocket442Olds: no
(09:52:16) whisupport: there are 3 smf board databases
(09:52:49) whisupport: 1 or all of them have been hacked
(09:53:09) whisupport: i can't even get the databases for them to respond
(09:54:15) whisupport: i am going to attempt to restore your databases from backup
(09:54:40) Rocket442Olds: ok
(09:54:51) whisupport: if we manage to get these recovered, you are going to have to slim these down
(09:54:59) whisupport: dramatically
(09:55:23) Rocket442Olds: ummm... how do i do that
(09:55:28) whisupport: and that advanced guestbook is way outdated...it's not even offered anymore
(09:55:32) whisupport: I have no idea
(09:55:40) whisupport: I have no idea of the information you have in them or anything
(09:56:02) Rocket442Olds: well the one smfforum is 2 years old, and has alot of posts
(09:56:31) whisupport: you need to archive the posts
(09:56:50) whisupport: you'll want to do some research in the smf forums
(09:57:13) Rocket442Olds: well i know i only need 2 of the 3 smf databases
(09:57:24) Rocket442Olds: i dont know why a third would be there
(09:57:56) whisupport: olds442_smf, olds442_smf1, and olds442_smf2
(09:58:32) Rocket442Olds: smf1 is from the board that i made as a mockup
(09:58:42) Rocket442Olds: i can delete that no problem
(09:58:46) whisupport: i don't think the restore is going to work because they are so big
(10:00:42) Rocket442Olds: so does that mean their pretty much gone, and i have to start from scratch?
(10:00:49) whisupport: i'm still trying
(10:00:52) whisupport: so i don't know yet
(10:00:58) whisupport: do you not have backups?
(10:01:20) Rocket442Olds: database ones from about 4 days ago
(10:01:31) Rocket442Olds: but they were the smf1 not 2
(10:01:41) Rocket442Olds: for the other site, the fbodyonline one
(10:02:17) Rocket442Olds: i have to go to a test
(10:02:21) Rocket442Olds: i'll be back in a few hours
(10:02:25) whisupport: ok
(12:17:31) Rocket442Olds: alright, i'm back
(13:13:48) Rocket442Olds: did the backups work, or no?
(14:27:18) whisupport: I can't save your databases
(14:27:24) whisupport: they have the server crashed again right now
(14:27:39) whisupport: you are going to have to start over
(14:27:54) whisupport: I've did everything I can, but your databases continue to triple in size
(14:28:05) whisupport: the partition is now out of space and all users on the server are down
(14:28:09) whisupport: I can't let this go on
(14:28:22) whisupport: your forums have been hacked
(15:19:55) Rocket442Olds: so basically, I have to start my whole site from scratch again... How do I even attempt to do that when I cant access anything to even delete or anything. I have older backups, but this is at least a month old
(15:20:31) whisupport: what do you mean you can't access anything
(15:20:33) whisupport: and look
(15:20:44) whisupport: it's not any of our faults that your forums were hacked
(15:20:48) whisupport: they were hacked before you even updated them
(15:21:04) whisupport: this has caused a nightmare on the server and who knows how many clients I am going to lose due to this
(15:21:31) Rocket442Olds: well.. see this is the thing, I didnt do it, and I was just asing a question, and now you come back rude like that
(15:21:34) Rocket442Olds: i didnt deserve that
(15:21:43) whisupport: I have spent this entire day trying to save your databases
(15:21:50) whisupport: I am not rude, I'm simply to the point

(15:22:03) whisupport: I don't like for anyone to lose anything
(15:22:14) whisupport: it drives me crazy when something is to the point that I can't fix it
(15:22:18) Rocket442Olds: like i planned for this to happen, and my forums are all up to date, they always have been
(15:22:32) whisupport: forums are hacked daily
(15:22:37) whisupport: this is a known fact
(15:22:52) whisupport: it doesn't matter if they are up to date or not, the hackings all derive from an updated forum
(15:22:57) whisupport: thus the need for more updates
(15:23:11) whisupport: I never said that you planned for this to happen
(15:23:25) whisupport: let me tell you what most hosting services would have done with your account
(15:23:37) whisupport: they would have immediately terminated you without even making an attempt to help you
(15:23:47) whisupport: they weigh the loss...you or their other clients
(15:24:12) whisupport: but I did not do that to you, instead I have spent my entire day fighting with this and have had users down for over 6 hours because of it
(15:24:31) whisupport: this means that those businesses did not function today, no email, no nothing
(15:24:48) whisupport: I have no removed your databases
(15:24:53) whisupport: they are still inside your account.
(15:24:59) whisupport: go back them up and see what you can do with them
(15:25:01) Rocket442Olds: i cant back them up myself though
(15:25:05) whisupport: yes you can
(15:25:07) whisupport: why can't you?
(15:25:10) Rocket442Olds: they dont even show up
(15:25:17) whisupport: they are showing for me
(15:25:19) Rocket442Olds: when i go to look at my databases in mysql
(15:25:25) whisupport: I'm inside your control panel right now
(15:25:30) whisupport: I'm looking at their tables
(15:25:41) Rocket442Olds: alright, their showing up now, a few minutes ago i only saw agbook
(15:25:54) whisupport: that's because I still had it all down trying to fix your stuff
(15:26:12) whisupport: right now, I'm sitting here watching them increase in size by the second
(15:26:19) whisupport: but I will not let the partition crash again
(15:26:30) whisupport: so back them up, download them to your computer, work on them there
(15:26:35) whisupport: because they are coming off the server
(15:26:48) whisupport: but by backing them up, you will at least have the data
(15:27:12) whisupport: just install a new forum, and restore your databases
(15:27:22) whisupport: but they need to be cleaned up first
(15:27:37) whisupport: actually right at this moment, I have them pretty cleaned up
(15:28:05) whisupport: so if you grab them now, you should be able to install a new forum and import the database and everything should be okay
(15:28:34) whisupport: but you need to understand something, and this can be verified by doing a simple google search on forums
(15:28:50) whisupport: they are the worse available scripts on the web, and are hacked daily
(15:29:33) whisupport: are you here?
(15:29:38) Rocket442Olds: yes
(15:29:44) Rocket442Olds: im exporting the sql right now
(15:29:54) whisupport: when you go to the first page of your control panel...look at the size of your databases now
(15:30:15) Rocket442Olds: 3.47mb
(15:31:14) whisupport: yes, whereas they were over 3 gigs before
(15:31:19) whisupport: that's because your forum is hacked
(15:31:19) Rocket442Olds: okay
(15:31:39) Rocket442Olds: so is my main smf database gone?
(15:31:50) whisupport: once you have them backed up. go remove the forums from fantastico
(15:31:54) Rocket442Olds: i see the old mockup for fbodyonline, and the new one (smf1 and smf2)
(15:32:00) Rocket442Olds: but i dont see the original for smf
(15:32:06) whisupport: yes, it was not saveable
(15:32:14) whisupport: I can probably recover it from backup
(15:32:18) whisupport: want me to try?
(15:32:37) Rocket442Olds: isnt that what is causing the sites to go down, going to do that?
(15:32:39) Rocket442Olds: so dont bother
(15:32:40) whisupport: no
(15:32:44) Rocket442Olds: oh
(15:32:49) Rocket442Olds: i have like a 1 month old one
(15:32:53) Rocket442Olds: i should be able to hanlde with that one
(15:32:56) whisupport: I will try to recover it but you immediately have to back it up and remove the forums
(15:33:08) whisupport: okay
(15:33:12) whisupport: but go remove those forums now
(15:33:18) whisupport: before this nightmare starts over again
(15:33:34) Rocket442Olds: they arent showing in fantastico
(15:33:48) whisupport: did you install them manually?
(15:33:48) Rocket442Olds: want me to delete their whole tables through phpmyadmin?
(15:34:02) whisupport: you will need to delete all of their files in your account as well
(15:34:07) whisupport: not just the databases
(15:34:14) whisupport: the files are infected too
(15:34:32) Rocket442Olds: okay
(15:34:33) whisupport: and you need to update your joomla too
(15:34:59) whisupport: your current version is 1.0.8, but the latest is 1.0.11 and I know there are a few security fixes in those updates
(15:35:55) Rocket442Olds: well let me delete these files for the forums
(15:35:59) whisupport: okay
(15:36:18) Rocket442Olds: so copying them over to my harddrive now does no good right?
(15:36:22) Rocket442Olds: since they're infected?
(15:36:36) whisupport: you can open them in excel or notepad and look through them
(15:36:42) whisupport: they should be fine
(15:36:50) whisupport: the databases that is
(15:36:53) whisupport: not the files
(15:37:11) whisupport: the files all need to be removed. that's where the hack stems from and taps into your databases
(15:37:18) Rocket442Olds: ok
(15:38:04) Rocket442Olds: when i connect with my ftp program its not doing anything
(15:38:23) Rocket442Olds: nm, got it
(15:38:27) whisupport: that's not how you do it
(15:38:35) whisupport: log into your phpmyadmin and click on export
(15:38:40) Rocket442Olds: i did that already
(15:38:47) whisupport: and save it to your hard drive
(15:38:53) Rocket442Olds: i exported both of those
(15:38:57) Rocket442Olds: the smf1 and smf2
(15:38:58) whisupport: you don't need to use ftp at all
(15:39:02) Rocket442Olds: and have them zipped on my harddrive
(15:39:05) whisupport: okay
(15:39:07) Rocket442Olds: but now i have to delete the files right?
(15:39:11) whisupport: yes
(15:39:26) Rocket442Olds: is ftp okay for that, or is there a better way?
(15:39:46) whisupport: no, that's fine
(15:39:48) Rocket442Olds: ok
(15:39:49) whisupport: I just ftp'd right in
(15:39:59) whisupport: not even a hiccup
(15:40:13) Rocket442Olds: yeah, i got in, for some reason my flashfxp froze the first time
(15:40:43) whisupport: I need to go take a break, but I am going to stay online. please keep me posted with your progress
(15:40:49) Rocket442Olds: okay
(16:18:35) Rocket442Olds: ok, files are deleted
(16:18:45) Rocket442Olds: both the main smfforums files, and the fbodyonline1's


I dont see how I could have done this, or how my forums did this.

I believe either way, she went from helping me to be angry with me, so needless to say I will be switching Hosting Services.
__________________
Camaro Forums || Firebird Forums
Check out vBulletin Setup for all your vBulletin SEO Questions & Tips
There is always someone faster, and in your case, that someone is Me
Reply With Quote
Old 11-06-2006, 11:15 PM   #2

Harlzard's Avatar

Title: Forum Addict

Points: 7,860, Level: 26Points: 7,860, Level: 26Points: 7,860, Level: 26
Level up: 27%, 290 Points neededLevel up: 27%, 290 Points neededLevel up: 27%, 290 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jan 2006

Posts: 1,909

Location: Australia

Harlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really nice
Send a message via MSN to Harlzard  
 
But you must understand that she spent the entire day trying to help you, that would have been very frustrating and other forums were down because of her help. I would get a bit angry, it would just happen naturually.

Sorry to hear about your forums, my forum was attacked by hackers over a 4 month period and that has ended in the forum being closed.
__________________
Metaltera.com :: Breed the Metal
Myspace Profile :: My profile!
Reply With Quote
Old 11-06-2006, 11:19 PM   #3
Ant

Ant is offline

Title: Member

Points: 2,020, Level: 12Points: 2,020, Level: 12Points: 2,020, Level: 12
Level up: 13%, 130 Points neededLevel up: 13%, 130 Points neededLevel up: 13%, 130 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Mar 2006

Posts: 116

Location: Christchurch, Dorset

Ant has a spectacular aura aboutAnt has a spectacular aura aboutAnt has a spectacular aura about
Send a message via AIM to Ant Send a message via MSN to Ant Send a message via Yahoo to Ant Send a message via Skype™ to Ant  
 
hey sorry about your forums, must be a huge nightmare.

I don't think you can blame her for being stressed, she seemed to be working very hard for you for the entire day. If this was a tech consultant out in the field that would of cost you a lot of money, at least £200 a day for anyone half decent, how much is your hosting a year?
__________________
Stargate Forum! - Discuss SG-1, Atlantis and other great Sci-Fi shows!!
DiscussDreams.com - Dream Discussion and Analysis
Just a Face? - Post a picture and see who the world thinks you are!
Reply With Quote
Old 11-06-2006, 11:49 PM   #4

LarryB's Avatar

Title: AF Lead Developer

Points: 6,450, Level: 23Points: 6,450, Level: 23Points: 6,450, Level: 23
Level up: 24%, 100 Points neededLevel up: 24%, 100 Points neededLevel up: 24%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Sep 2005

Posts: 1,186

Location: OHIO, US

LarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud of
Send a message via MSN to LarryB  
 
To be honest. Sounds like an incompetent host to me. Sorry if I offend someone. There is no need to remove the suspension for them to do something. It would have been as simple as commenting out the virtual hosts in their config file temporarily to keep it from getting hit. Then removing the suspension so you could get to the file system.
__________________
Do not post your PF private key in public.

Did I help you with this post? If so, pls click the rep button or send money.
Reply With Quote
Old 11-07-2006, 01:19 AM   #5

Rocket 442's Avatar

Title: Apprentice

Points: 4,057, Level: 18Points: 4,057, Level: 18Points: 4,057, Level: 18
Level up: 19%, 193 Points neededLevel up: 19%, 193 Points neededLevel up: 19%, 193 Points needed
Activity: 12%Activity: 12%Activity: 12%

Join Date: Jul 2006

Posts: 487

Location: Buffalo, NY

Rocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to behold

Recent Blog: Workload update
Send a message via AIM to Rocket 442 Send a message via MSN to Rocket 442  
 
Quote:
Originally Posted by LarryB View Post
To be honest. Sounds like an incompetent host to me. Sorry if I offend someone. There is no need to remove the suspension for them to do something. It would have been as simple as commenting out the virtual hosts in their config file temporarily to keep it from getting hit. Then removing the suspension so you could get to the file system.
Well Thats what one of my friends said. And he also said she should have been able to spot where the php script was that messed it up.
__________________
Camaro Forums || Firebird Forums
Check out vBulletin Setup for all your vBulletin SEO Questions & Tips
There is always someone faster, and in your case, that someone is Me
Reply With Quote
Old 11-07-2006, 03:47 AM   #6

LarryB's Avatar

Title: AF Lead Developer

Points: 6,450, Level: 23Points: 6,450, Level: 23Points: 6,450, Level: 23
Level up: 24%, 100 Points neededLevel up: 24%, 100 Points neededLevel up: 24%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Sep 2005

Posts: 1,186

Location: OHIO, US

LarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud ofLarryB has much to be proud of
Send a message via MSN to LarryB  
 
spotting the script can be tricky, but killing the website that is doing it is a simple apache reconfig and restart.
__________________
Do not post your PF private key in public.

Did I help you with this post? If so, pls click the rep button or send money.
Reply With Quote
Old 11-07-2006, 09:22 PM   #7

Ryan's Avatar

Title: Administrator

Points: 47,649, Level: 67Points: 47,649, Level: 67Points: 47,649, Level: 67
Level up: 68%, 701 Points neededLevel up: 68%, 701 Points neededLevel up: 68%, 701 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Sep 2005

Posts: 10,246

Location: Athens, GA

Ryan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond reputeRyan has a reputation beyond repute
 
 
Sorry to hear about your struggles...it's never fun to work through this kind of stuff...I read the first half of that conversation and skimmed through the rest, but it sounds like you at least took something away from everything, right? The files and the database?

I wouldn't know where to start, but it sounds like you need to open them up and figure out what went wrong...You might also want to try SMF, because you never know, they could be familiar with whatever problem this is.

Good luck
__________________
...some super-sweet signature
Reply With Quote
Old 11-08-2006, 12:55 AM   #8

Rocket 442's Avatar

Title: Apprentice

Points: 4,057, Level: 18Points: 4,057, Level: 18Points: 4,057, Level: 18
Level up: 19%, 193 Points neededLevel up: 19%, 193 Points neededLevel up: 19%, 193 Points needed
Activity: 12%Activity: 12%Activity: 12%

Join Date: Jul 2006

Posts: 487

Location: Buffalo, NY

Rocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to beholdRocket 442 is a splendid one to behold

Recent Blog: Workload update
Send a message via AIM to Rocket 442 Send a message via MSN to Rocket 442  
 
Tried SMF, and that is the one thing they lack... Support.

I'm still not convinced it was my forums, but I guess the host knows better than me. I reinstalled my one forum (www.fbodyonline.com) and she deleted the database of my other one (that I have had for 2 years) without letting me know.

So then I find out for some reason the automatic backups i set up arent working correctly, so I'm down to 2 months ago for domesticdisturbance.us forums.

And On top of that, for some reason my whole hosts sites, as well as mine have been down the past 2 hours again. Yay.
__________________
Camaro Forums || Firebird Forums
Check out vBulletin Setup for all your vBulletin SEO Questions & Tips
There is always someone faster, and in your case, that someone is Me
Reply With Quote
Old 11-14-2006, 05:25 PM   #9

JAMMAN's Avatar

Title: Rookie

Points: 1,643, Level: 11Points: 1,643, Level: 11Points: 1,643, Level: 11
Level up: 12%, 207 Points neededLevel up: 12%, 207 Points neededLevel up: 12%, 207 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: May 2006

Posts: 26

JAMMAN is on a distinguished road
 
 
If you have access to phpMyAdmin you can "repair all tables" and that error will go away most of the time. That's a corrupted table error, out of the last 10 I attempted to fix 9 of them came back healthy. Since you know the table name it will be easier, your smf_log_activity table has become unstable.
__________________
We are not resellers.
Experienced shared & dedicated hosting
Reply With Quote