Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Not a member yet? Click here to register.
Forgot Password?

orentraff.cn hacker?

Asked Modified Viewed 5,525 times
P
Puma
P
Puma 10
RESISTANCE IS FUTILE EARTHLINGS !!!
  • Member, joined since
  • Contributed 142 posts on the community forums.
  • Started 22 threads in the forums
  • Started this discussions
asked
Member

Hi people..

When i navigate trough my sites i see a unknown address appearing for a fraction of a second,it mostly appears when i use the back & forward buttons in my browserwindow.

www.uwkabaal.com/images/orentraff.gif

I used Google to know more about that orentraff.cn domain and it seems it is a domains that's hosted in China and that it is some kind of hacker.
But no idea what this hack (if it is a hack) does.
I can't find any damage or alterations that was done to my sites.
Anyone else that experienced this problem?


This is what i found using Google:

"orentraff.cn is a domain name. The code was calling something from
another server into an invisible iframe. That something is probably
malicious."
Edited by Puma on 29-05-2008 03:25,
0 replies

26 posts

X
Xessive
X
I am not always right, but I'm never wrong.
http://www.xessive.nl
  • Senior Member, joined since
  • Contributed 327 posts on the community forums.
  • Started 4 threads in the forums
answered
Senior Member

Quote

MrSimple wrote:
What can we do to prevent this injection to our sites?
Make maincore unwritable? Remove custom pages? Or something else?


run the latest en completely un-modded version of PHPFusion...
Whenever you use a infusion from 3rd party the chance is there that some code
will be unsafe and vulnarable to SQL injections...

I don't know if there's a tool of some kind which can check PHP code for
sloppy code which makes SQL injections possible.
If someone knows about such a tool please post it here..!!
0 replies
M
muscapaul
M
Paul

Time flies like an arrow, fruit flies like banana (Groucho Marx)

Sites: Diptera.info (site owner); Online-Keys.net (site owner); Sciomyzidae.info (site co-owner); muscapaul.com (defunct; site owner)
  • Veteran Member, joined since
  • Contributed 1,075 posts on the community forums.
  • Started 8 threads in the forums
answered
Veteran Member

Quote

MrSimple wrote:
What can we do to prevent this injection to our sites?
Make maincore unwritable? Remove custom pages? Or something else?

In v6 a hacker only needs the password of an administrator with Custom Page access to be able to do this. In v7 it will be more difficult to do the same thing as the culprit needs to acquire two passwords: a login password of an administrator and that admin's admin password that he/she has set to perform a number of admin actions (among those work on Custom Pages). Another new security feature in v7.
0 replies
S
starefossen
S
www.postexus.com - Follow Postexus on Facebook.
  • Senior Member, joined since
  • Contributed 359 posts on the community forums.
  • Started 20 threads in the forums
answered
Senior Member

Prevent your site from getting hacked:

1. Allways run the latest and greates version of the system (PHPFusion)

2. Be carefull with infusions / mods made by 3. party.

3. Never give custom pages / panels access to admins who don't need it. Only give such access to those you trust.

4. MySQL, FTP and your admin user password must be different!

5. Change all passwords on a regular basis

6. Never use your admin user password as a user password at another site!
0 replies
A
alcazar
A
Alcazar
nach Diktat spazierengegangen
  • Senior Member, joined since
  • Contributed 247 posts on the community forums.
  • Started 5 threads in the forums
answered
Senior Member

For dealing with the cracker / script kiddie just send homdax on a trip to china.
(like he did with the turkish ones :P )
0 replies
H
Homdax
H
Homdax 10
  • Fusioneer, joined since
  • Contributed 2,247 posts on the community forums.
  • Started 108 threads in the forums
answered
Fusioneer

Sorry, not going to China until later this year for Olympics System Support Crack Down.
0 replies

Labels

None yet

Statistics

  • Views 0 views
  • Posts 26 posts
  • Votes 0 votes
  • Topic users 12 members

0 participants

Notifications

Track thread

You are not receiving notifications from this thread.

Related Questions

Not yet