Symptom: A user of my site brought to my attention that it is not working right now. An error in a particular php file occurs in my phpbb installation. I have changed nothing in that installation for over a year, and now it has syntax errors!
Diagnosis: I notice that the particular file that contains the error was edited just two days ago, though I know I didn't touch it at all. Other files were edited at the same time. I might have been hacked.
Solution: Restore files from backup copy
Problem with solution: both files have permissions of 644 (common to most of the original files), but they also have ownership of 'root', which makes those files unique. This means that I cannot change the permissions of those files, or delete them so they can be replaced. I have tried deleting them both by FTP and by directadmin, neither will allow it.
Solution to problem: Please go into the files of onet.frih.net using root privileges and delete these files:
/domains/onet.frih.net/public_html/community/includes/functions.php
/domains/onet.frih.net/public_html/community/includes/index.htm
/domains/onet.frih.net/public_html/community/language/index.htm
/domains/onet.frih.net/public_html/community/language/lang_english/index.htm
/domains/onet.frih.net/public_html/community/language/lang_english/email/index.htm
/domains/onet.frih.net/public_html/community/templates/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/images/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/index_frameset.tpl
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/page_footer.tpl
/domains/onet.frih.net/public_html/community/images/index.htm
/domains/onet.frih.net/public_html/community/images/avatars/index.htm
/domains/onet.frih.net/public_html/community/images/avatars/gallery/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/index_frameset.tpl
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/page_footer.tpl
/domains/onet.frih.net/public_html/community/templates/digiTech/images/
/domains/onet.frih.net/public_html/community/docs/codingstandards.htm
/domains/onet.frih.net/public_html/community/docs/README.htm
/domains/onet.frih.net/public_html/community/docs/INSTALL.htm
/domains/onet.frih.net/public_html/community/docs/FAQ.htm
/domains/onet.frih.net/public_html/community/docs/CHANGELOG.htm
/domains/onet.frih.net/public_html/community/db/index.htm
/domains/onet.frih.net/public_html/community/cache/index.htm
Then tell me that they've been deleted (preferably by e-mail: equinedream@lavabit.com) so that I can replace them with correct backup files. I realize that this is a lot of trouble, to delete so many files, but it is very important to me, and could even perhaps be a security risk to the whole server. All of these files could contain malicious code, and I can't delete them.
I'm posting this as a guest because my current internet connection is intermittent. So, if I did log on, I might soon be logged off and back on again, which would erase the history of what threads I've read, which could cause me to miss things.
To prove that I actually am ocalhoun, and not an impostor trying to get some files deleted for sheer mischief, I'll give you something only I could get, that you can verify, and that is safe for everyone to see:
Line number 50 in /domains/equinedream.org/public_html/stories/c_auth_edit.php is:
Nobody else worked on those files, and nobody else could download the php file and read it.
Thank you!
Diagnosis: I notice that the particular file that contains the error was edited just two days ago, though I know I didn't touch it at all. Other files were edited at the same time. I might have been hacked.
Solution: Restore files from backup copy
Problem with solution: both files have permissions of 644 (common to most of the original files), but they also have ownership of 'root', which makes those files unique. This means that I cannot change the permissions of those files, or delete them so they can be replaced. I have tried deleting them both by FTP and by directadmin, neither will allow it.
Solution to problem: Please go into the files of onet.frih.net using root privileges and delete these files:
/domains/onet.frih.net/public_html/community/includes/functions.php
/domains/onet.frih.net/public_html/community/includes/index.htm
/domains/onet.frih.net/public_html/community/language/index.htm
/domains/onet.frih.net/public_html/community/language/lang_english/index.htm
/domains/onet.frih.net/public_html/community/language/lang_english/email/index.htm
/domains/onet.frih.net/public_html/community/templates/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/images/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/index.htm
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/index_frameset.tpl
/domains/onet.frih.net/public_html/community/templates/subSilver/admin/page_footer.tpl
/domains/onet.frih.net/public_html/community/images/index.htm
/domains/onet.frih.net/public_html/community/images/avatars/index.htm
/domains/onet.frih.net/public_html/community/images/avatars/gallery/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/index.htm
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/index_frameset.tpl
/domains/onet.frih.net/public_html/community/templates/digiTech/admin/page_footer.tpl
/domains/onet.frih.net/public_html/community/templates/digiTech/images/
/domains/onet.frih.net/public_html/community/docs/codingstandards.htm
/domains/onet.frih.net/public_html/community/docs/README.htm
/domains/onet.frih.net/public_html/community/docs/INSTALL.htm
/domains/onet.frih.net/public_html/community/docs/FAQ.htm
/domains/onet.frih.net/public_html/community/docs/CHANGELOG.htm
/domains/onet.frih.net/public_html/community/db/index.htm
/domains/onet.frih.net/public_html/community/cache/index.htm
Then tell me that they've been deleted (preferably by e-mail: equinedream@lavabit.com) so that I can replace them with correct backup files. I realize that this is a lot of trouble, to delete so many files, but it is very important to me, and could even perhaps be a security risk to the whole server. All of these files could contain malicious code, and I can't delete them.
I'm posting this as a guest because my current internet connection is intermittent. So, if I did log on, I might soon be logged off and back on again, which would erase the history of what threads I've read, which could cause me to miss things.
To prove that I actually am ocalhoun, and not an impostor trying to get some files deleted for sheer mischief, I'll give you something only I could get, that you can verify, and that is safe for everyone to see:
Line number 50 in /domains/equinedream.org/public_html/stories/c_auth_edit.php is:
| Code: |
| if ($ad_type == "custom") //only try to get the ad file if there actually is one. |
Nobody else worked on those files, and nobody else could download the php file and read it.
Thank you!
