osCmax v2.5 User Manual
Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19

mainpage.php contents replaced

This is a discussion on mainpage.php contents replaced within the osCmax v2 Installation issues forums, part of the osCmax v2.0 Forums category; Hi, I am new to this forum but found it really helpful with this thread. I too have my mainpage ...

      
  1. #11
    Lurker
    Join Date
    Sep 2010
    Posts
    2
    Rep Power
    0


    Default Re: mainpage.php contents replaced

    Hi,

    I am new to this forum but found it really helpful with this thread. I too have my mainpage contents replaced in August. My host provider did a restore for me to fix it. Then it happened again but luckily I kept a copy in my PC after the first experience so I can update thru the oscommerce admin, phew!

    Subsequently, my website cannot be displayed so we discovered there is a new empty file index.html loaded, so that was got rid off. But the next day it is created again so have to get rid again. After reading this thread, I also found there are so many goog*.php files in my image folder and public folder. I was so shock and have got them deleted and block all access except my host and myself. Still not sure any more kept secretly somewhere in the database.

    I checked those files mentioned in the thread like checkout_process and etc and they are still the old version so I am not too sure what else to check as file manager in cpanel never gives the last changed dates for files.

    Any advice will be really great.

  2. #12
    osCMax Development Team
    ridexbuilder's Avatar
    Join Date
    Jul 2008
    Location
    Haggisland
    Posts
    3,014
    Rep Power
    36


    Lightbulb Re: mainpage.php contents replaced

    Guys, I'm sorry but I really don't get the point of trying to do a thorough post-mortem. The time spent doing it can be used much more fruitfully, IMO.

    Look at the wiki for security matters, do the tidy up, then move on.
    Attempted hacks (cracks actually) on servers happen every day. Just make sure you close the doors and have a reliable hosting provider.



    [An FTP client normally has an option to show the modified column - though it might be an idea to download the cracked site and do an offline compare with a known clean version - assuming that your PC is secured.]
    Last edited by ridexbuilder; 09-21-2010 at 05:14 AM.
    Hosting plans with installation, configuration, contributions, support and maintenance.

  3. #13
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,907
    Rep Power
    568


    Default Re: mainpage.php contents replaced

    Quote Originally Posted by dani View Post
    can he/she use define_language.php file?
    Current versions of osCmax do not have the define_language.php file anymore, due to the security problems it has. If you still have it in your install, you are using an outdated version of osCmax and should get current with security patches.
    Michael Sasek
    osCMax Developer


    osCmax Installation Service
    - Have our professionals install osCmax on your server - same day service!
    osCmax 2.5 User Manual - the must have beginners guide to osCmax v2.5

    Stay Up To Date with everything osCMax:
    Free osCmax Newsletters - Security notices, New Releases, osCMax News
    osCmax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  4. #14
    New Member
    Join Date
    Sep 2005
    Posts
    10
    Rep Power
    0


    Default Re: mainpage.php contents replaced

    Quote Originally Posted by ridexbuilder View Post
    Guys, I'm sorry but I really don't get the point of trying to do a thorough post-mortem. The time spent doing it can be used much more fruitfully, IMO.

    Look at the wiki for security matters, do the tidy up, then move on.
    You're right that it would be easier to skip the post-mortem.

    I started this thread by asking about this hack and kept searching for others who encountered this hack. I found various threads elsewhere talking about it and after several days of no activity in this thread I posted my findings here.

    tcshadow was helpful by mentioning the goog1*.php files and providing a link to the cre loaded forums.

    I wanted to contribute search-able content about my findings and trial solutions so others who encounter this will have a little extra info to help them clean up the mess.

    I try to keep an eye on, and adhere to security measure posted in the security wiki but this one slipped thought he cracks.


    I hope my etiquette is not inappropriate by rambling about my findings and results.

  5. #15
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,907
    Rep Power
    568


    Default Re: mainpage.php contents replaced

    Keep on rambling, I cannot speak for anyone else, but I for one appreciate more information than less.
    Michael Sasek
    osCMax Developer


    osCmax Installation Service
    - Have our professionals install osCmax on your server - same day service!
    osCmax 2.5 User Manual - the must have beginners guide to osCmax v2.5

    Stay Up To Date with everything osCMax:
    Free osCmax Newsletters - Security notices, New Releases, osCMax News
    osCmax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  6. #16
    osCMax Development Team
    ridexbuilder's Avatar
    Join Date
    Jul 2008
    Location
    Haggisland
    Posts
    3,014
    Rep Power
    36


    Default Re: mainpage.php contents replaced

    I wasn't complaining, so much as reflecting.
    The sharing of information is key to a good community.
    Hosting plans with installation, configuration, contributions, support and maintenance.

  7. #17
    New Member
    Join Date
    May 2010
    Posts
    29
    Rep Power
    0


    Default Re: mainpage.php contents replaced

    I was considering security as I am in the process of creating a store, good info in the thread. I think I need to check the wiki link

  8. #18
    Lurker
    Join Date
    Sep 2010
    Posts
    3
    Rep Power
    0


    Default Re: mainpage.php contents replaced

    my site hacked again by goog1 ... file
    i set password for admin folder but..

  9. #19
    osCMax Development Team
    ridexbuilder's Avatar
    Join Date
    Jul 2008
    Location
    Haggisland
    Posts
    3,014
    Rep Power
    36


    Lightbulb Re: mainpage.php contents replaced

    You did thoroughly scan your client machines? Your normal anti-vir program, plus for example Malwarebytes, plus one other. This is in addition to following all of the points in the wiki, with regards the server.
    If you're on a shared server, maybe it's time to look elsewhere.
    Hosting plans with installation, configuration, contributions, support and maintenance.

Page 2 of 2 FirstFirst 12

Similar Threads

  1. Replies: 17
    Last Post: 02-10-2010, 12:56 PM
  2. javascript scroller on mainpage.php (Define mainpage)
    By zuqaili in forum osCmax v2 Customization/Mods
    Replies: 7
    Last Post: 04-30-2007, 09:51 PM
  3. Remove total from 'cart contents' box
    By icecold in forum osCmax v2 Customization/Mods
    Replies: 2
    Last Post: 04-27-2006, 03:43 AM
  4. Category index box contents disappear
    By groone in forum osCMax v1.7 Installation
    Replies: 1
    Last Post: 08-04-2004, 02:37 AM
  5. Editing Categories Box Contents
    By smf in forum osCommerce 2.2 Modification Help
    Replies: 0
    Last Post: 04-26-2003, 09:50 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •