Talk Arcades: Forum for Arcade Webmasters    

  Talk Arcades > Arcades > Webmastering

Welcome to Talk Arcades, the premier forum for arcade webmasters.

You are currently viewing our boards as a guest. By joining our community you will be able to make posts, communicate privately with other arcade webmasters and participate in our Live Marketplace. Registration is easy, so please join us today!

Reply
 
LinkBack Thread Tools Display Modes
Old 10-26-2006, 07:37 PM   #1 (permalink)
v12kid
Preferred Member
 
v12kid's Avatar
 
Join Date: Jun 2006
Posts: 178
v12kid is on a distinguished road
Send a message via AIM to v12kid Send a message via MSN to v12kid Send a message via Skype™ to v12kid


Default Been hacked, need help!

Is anyone good with GSS? My arcade was hacked and is redirecting to another arcade, this is very ****ty and I cant seem to figure out where the code is to redirect?

AIM me at v12kid asap if you can

thanks
__________________
The Boss Is Away!
v12kid is offline  
Digg this Post!
Reply With Quote
Old 10-26-2006, 10:40 PM   #2 (permalink)
admin
Preferred Member
 
Join Date: May 2006
Location: Planet Earth
Posts: 190
admin is on a distinguished road
Send a message via MSN to admin


Default

I just saw your message and went to your site but it seems to be fixed now.

ANy idea how the hacker got in and what got changed? This info might be useful for people who have GSS.
admin is offline  
Digg this Post!
Reply With Quote
Old 10-27-2006, 07:18 AM   #3 (permalink)
Entertainment-CMS.com
ECMS Staff
Full Member
 
Entertainment-CMS.com's Avatar
 
Join Date: Jul 2006
Location: England
Posts: 70
Entertainment-CMS.com is on a distinguished road


Default

TheBossIsAway looks fine to me.
__________________
Entertainment-CMS.com Out Soon

View Status --> Entertainment-CMS DEVELOPMENT BLOG <-- View Status
Entertainment-CMS.com is offline  
Digg this Post!
Reply With Quote
Old 10-27-2006, 09:58 AM   #4 (permalink)
Hans
onArcade Staff
Full Member
 
Hans's Avatar
 
Join Date: Jun 2006
Posts: 50
Hans is on a distinguished road


Default

It looks also fine to me, but if you are still hacked then you should check support forums of that script, I am sure you'll find help from there.
Hans is offline  
Digg this Post!
Reply With Quote
Old 10-27-2006, 06:16 PM   #5 (permalink)
bigarte
Contributing Member
 
Join Date: Jun 2006
Location: Australia
Posts: 33
bigarte is on a distinguished road
Send a message via MSN to bigarte


Default

This is taken directly from the Author's site:-

Quote:
Various Security Problems Updated: 04-18-2006

Dear GameSiteScript Clients,

It has recently been brought to my attention that there is a hacker exploiting both "user stupidity" security issues and issues with certain servers that enable anyone to browse and view files on the server. GameSiteScript has helped this exploit along by allowing the uploading of files via the game submission feature.

You should read this whole e-mail. The issues may apply to you.

If you accept game submissions on your site via the "Submit" feature of GSS, and you have no .htaccess "deny from all" file in /uploadfiles/, and you have directory indexes enabled, you may be vulnerable. Don't find out the hard way.

I've listed things you can do to make sure you're secure. Any of the following will solve the problem. You don't need to take all the steps listed, just one.


1. Put a .htaccess file containing the code "deny from all" in your /uploadfiles/ folder.
2. Disable "directory indexes." This can be accomplished with a .htaccess file containing "Options -Indexes" placed.
3. Disable PHP and scripts in the /uploadfiles/ folder. Contact your host asking how to do this.
4. Install security software on your server (you must be the server owner) that stops "shell" style PHP scripts from running. If you don't know what I'm talking about, ask your server management company.

Additionally, I have had a report of a site being redirected to another site. How did the hacker achieve this? He modified the index.php file of the site! Whatever you do, DO NOT ALLOW PHP TO WRITE YOUR FILES. DO NOT CHMOD THEM TO 0777!

Don't let your GameSiteScript sites be hacked!

Also, another message for those of you that haven't changed the default admin username/password:

Do not leave your default username and password as admin/admin. Anyone can login to your admin area and modify your site. This is a huge issue with users that somehow think people on the Internet are nice and friendly and won't hack your site if they see an opportunity.

If you're not sure if you're secure or not, feel free to e-mail me your site details and I'll look into it for you.

Best Regards,
Louis Reingold
Hope it helps.
bigarte is offline  
Digg this Post!
Reply With Quote
Old 10-27-2006, 09:14 PM   #6 (permalink)
Entertainment-CMS.com
ECMS Staff
Full Member
 
Entertainment-CMS.com's Avatar
 
Join Date: Jul 2006
Location: England
Posts: 70
Entertainment-CMS.com is on a distinguished road


Default

In other words, you can upload php scripts, then use them on the server.
__________________
Entertainment-CMS.com Out Soon

View Status --> Entertainment-CMS DEVELOPMENT BLOG <-- View Status
Entertainment-CMS.com is offline  
Digg this Post!
Reply With Quote
Old 10-27-2006, 09:18 PM   #7 (permalink)
bigarte
Contributing Member
 
Join Date: Jun 2006
Location: Australia
Posts: 33
bigarte is on a distinguished road
Send a message via MSN to bigarte


Default

That's correct. It was a big problem back when this alert was issued. Haven't heard much about it since then (except for any peeps. using the nulled versions).

PS: I'm not suggesting that V12kid is using anything other than a fully licensed version BTW.
bigarte is offline  
Digg this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sites been hacked SpankyBear Webmastering 12 07-09-2007 01:47 PM
Easily Hacked Duality GameScript 5 07-20-2006 12:24 PM


All times are GMT -6. The time now is 01:50 AM.


Powered by vBulletin® Version 3.6.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 RC6
© TalkArcades.com
Forum - Register - Calendar - Memberlist - FAQ - Search