Site hacked from Russia?

The Webscribble Webdate Users Lounge. This Forum Is For Webdate Site Owners To Talk About Anything Other Than Bugs. Share Experience. Find Partners Or Anything Else.

Site hacked from Russia?

Postby mutton on Sat Jun 28, 2008 8:53 pm

Here's an email from a customer of mine....one who has been a member of my site for about 2 years:

DEAR (Site name removed),
Thoought you would like to know that I think your system has been "hacked". I got the e-mail message below. Your's is one of the few sites that I use this e-mail account and I have not sent any messages via it for a while.
Just an F.Y.I.
(user name removed)

Please note: forwarded message attached

Hello from Tatyana!
I saw your structure on a site (site name remove)com, but my registration there already has ended, therefore I write to you on a structure.
I search serious relations; the partner in life is necessary for me!
I want to tell a little about myself: I live in Russia.
My friends count me the cheerful, interesting girl!
I romantic believe in fairy tales, I want to find the prince!
I love music, cinema, to read books!
I hope, I shall like you!
Now I write to you with e-mail my friends.
If I have interested you, please write to me on mine e-mail: shetatyana@yahoo.com
Answer me, please, questions:
Whether you want children?
What do you want from a life and from our acquaintance?
I shall wait from you for the answer, and tell to me a little about myself.
Write to me.
I wish you successful day.
Yours Tatyana.


Do you think this is possible? Back door from Webscribble? Some other way? We only ever had one Russian registration, which was not approved.
mutton
 
Posts: 100
Joined: Mon Feb 11, 2008 11:47 pm

Re: Site hacked from Russia?

Postby paul on Sat Jun 28, 2008 11:37 pm

I have recieved these same emails from a russian site that I worked on...

there is a backdoor into the script because anyone can extract emails from the preview profile page if they know the trick

to protect your members from this hack

open the file at

engine/pages/preview_profile.php

the seventh line up from the bottom is:

<td width="60%">'.$aMember["email"].'</td>

remove this line and save the file

this will eliminate the hack/back door...

Paul
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby mutton on Sat Jun 28, 2008 11:46 pm

In my site that line was already commented out as part of the changes you made.
mutton
 
Posts: 100
Joined: Mon Feb 11, 2008 11:47 pm

Re: Site hacked from Russia?

Postby paul on Sat Jun 28, 2008 11:57 pm

It needs to be removed completely

commenting out blocks it from view on the screen

but they can still see the email in the commented out area if a bot is viewing the html source

I took it out for you.

Paul
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby sddarkman619 on Sun Jun 29, 2008 12:23 am

what version of webdate is this?
sddarkman619
 
Posts: 19
Joined: Sun Jun 01, 2008 11:55 pm

Re: Site hacked from Russia?

Postby paul on Mon Jun 30, 2008 7:45 pm

Version 3
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby mutton on Wed Jul 02, 2008 12:48 am

Since it requires a username and password to view the preview members display, why are hackers able to get in? Is it a backdoor?
mutton
 
Posts: 100
Joined: Mon Feb 11, 2008 11:47 pm

Re: Site hacked from Russia?

Postby paul on Wed Jul 02, 2008 4:55 pm

you need not log in to preview profiles

and if you know the hack you can also preview in admin mode

I will not go into detail as this would create more problems

Paul
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby Levendi on Mon Jul 14, 2008 2:41 am

After we did this people cannot buy stamps anymore.

:(

help
Levendi
 
Posts: 3
Joined: Tue Jan 29, 2008 7:27 am

Re: Site hacked from Russia?

Postby mutton on Mon Jul 14, 2008 7:06 am

what are stamps anyhow? I've never seen any option on my site to buy them.
mutton
 
Posts: 100
Joined: Mon Feb 11, 2008 11:47 pm

Re: Site hacked from Russia?

Postby paul on Mon Jul 14, 2008 6:15 pm

Stamps are another form of payment through the script... by having members pay per contact..

I do not understand what your saying levendi?

"after we did this"

after you did what?

Paul
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby Levendi on Tue Jul 15, 2008 9:12 am

this after we did this people cannot buy stamps any more

to protect your members from this hack

open the file at

engine/pages/preview_profile.php

the seventh line up from the bottom is:

<td width="60%">'.$aMember["email"].'</td>

remove this line and save the file

this will eliminate the hack/back door...
Levendi
 
Posts: 3
Joined: Tue Jan 29, 2008 7:27 am

Re: Site hacked from Russia?

Postby paul on Tue Jul 15, 2008 6:17 pm

this file only affects the profile display to administrators and would in noway affect your payment system...

make sure you did not change any permissions on your other files

Paul
User avatar
paul
Site Admin
 
Posts: 264
Joined: Sat Jan 26, 2008 7:30 pm
Location: Newington,Ct,USA

Re: Site hacked from Russia?

Postby Gnus on Wed Jul 16, 2008 1:35 pm

The code is for a benefit the administrator to view info about a members profile more than what the regular member would see such as email, ip and login and shows at the bottom of preview profile when the admin is viewing the profile. Just something extra, not really needed. I have removed all that from mine. No way that would affect payments by removing it.

Gary
Gnus
 
Posts: 10
Joined: Mon Jun 30, 2008 10:46 pm


Return to Webdate Users Lounge

Who is online

Users browsing this forum: No registered users and 5 guests

cron