security problems

Hi,

I am running a patched version of 6.1 (upgraded from 6.0) and keep on getting hacked.

I have the following config:

register_globals = Off
magic_quotes_gpc = On
SAFE_MODE = OFF
allow_url_fopen = On
mod_rewrite = On
RewriteEngine = On

Here is the message I recieved from my host:

Your hosting account  has been attacked via an insecure PHP
script.

-  the following malicious files have been uploaded to your webspace:

./*******/media/ocra.php
./******/plugins/safehtml/writable.php
./openstar_4.01/index5.php
./*******/plugins/safehtml/HTMLSax3/popup.php
./t*******/ray/modules/chat/data/sounds/popup.php




Having disabled these files, we will unlock your account after this e-mail.
Please understand that the temporary lock of your account was necessary to
protect our infrastructure.

To reestablish the security of your webspace, please proceed now as follows:

Secure all security leaks in your scripts. We found successful
exploits through at least the following:

******* /index.php
$config[ppa_root_path],sourcedir,include_path,root_path,id,prefix,error_log,dir[plugins],sinpaTH,path[docroot],sIncPath,jamroom[jm_dir],idcat,buku_tamu,DOCUMENT_ROOT,page,abg_path,path_escape,pagename,pag,errors,WN_BASEDIR,root_dir,i,custompluginfile[],l,p,s,sbp,x,THEME_DIR
******** /Dolphin/
$config[ppa_root_path],sourcedir,include_path,root_path,id,prefix,error_log,dir[plugins],sinpaTH,path[docroot],sIncPath,idcat,buku_tamu,page,path_escape,pagename,pag,errors,WN_BASEDIR,root_dir,i,custompluginfile[],l,p,s,sbp,x,THEME_DIR

249     /********* /Dolphin/rate.php/plugins/safehtml/safehtml.php
$dir[plugins],dir[plugins]%7Dsafehtml




What can I do to stop these hackers?


the Fluid Druid
Quote · 18 Aug 2008

you know i got the same problem i was hacked 4 times in one day. I even blamed my server company. I would like to know is this script safe to use? I am starting to think different since i been hacked so many times. Whats the poing in building a site if it keeps getting hacked. Jaguarpc told me they can secure my website for $75.00 a hour and im thinking it was them that probably hacked me since now they want me to pay a high fee to secure my site

the only thing you can really do is block there ip address but they most likely faked there ip address also you can hire someone to fix the security leaks.

Quote · 18 Aug 2008

v6.1.4 fixes all the hacking problems  ..... 
.

Quote · 18 Aug 2008

No, it doesn't.

I had upgraded the one installation from 6.0.x to 6.1 and then applied the patches.

The other was a fresh 6.1.0 install with all the patches, which brought both up to 6.1.4.

I also recieved error e-mails during the hacker attack saying:

Database error in The Fluid Druid Network
Query:

SELECT DISTINCT
`Profiles`.*,
(LastNavTime > SUBDATE(NOW(), INTERVAL 5 MINUTE)) as is_onl

FROM Profiles
INNER JOIN `Tags` USING( `ID` ) WHERE Status = 'Active' AND `Tags`.`Type` = 'profile' AND ( `Tags`.`Tag` = 'hit2' )
ORDER BY
1 DESC,
Profiles.LastLoggedIn DESC
LIMIT 0, 10


Mysql error:
Unknown column 'LastNavTime' in 'field list'

Found error in file *******/Dolphin/search_result.php

at line 575. Called db_res function
with erroneous argument #0

Debug backtrace:
Array
(
[1] => Array
(
[file] => /******/Dolphin/search_result.php
[line] => 575
[function] => db_res
[args] => Array
(
[0] =>
SELECT DISTINCT
`Profiles`.*,
(LastNavTime > SUBDATE(NOW(), INTERVAL 5 MINUTE)) as is_onl

FROM Profiles
INNER JOIN `Tags` USING( `ID` ) WHERE Status = 'Active' AND `Tags`.`Type` = 'profile' AND ( `Tags`.`Tag` = 'hit2' )
ORDER BY
1 DESC,
Profiles.LastLoggedIn DESC
LIMIT 0, 10

)

)

)


Called script: /Dolphin/search_result.php

Request parameters:
Array
(
[tag] => hit2
)

Quote · 18 Aug 2008

yea i keep getting hacked also its so damn irratating im not using dolphin anymore. Dolphin has way to many holes and i get attacked all the time

Quote · 27 Aug 2008

you are correct sammie

Kids first
Quote · 27 Aug 2008
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.