Help - Search - Members - Calendar
Full Version: My Mt Blogs Just Got Hacked
Movable Type Community Forum > Other Product Discussion > Bugs and Odd Behavior
ultramalcolm
Okay...so, my three MT 3.2 blogs just got hacked.

All three now read:

0wned by PSYCH@
Fuck israel. No waR.

Now, I don't think this was an ftp security breach, since all my other sites are fine. Only those powered by MT were affected.

Fortunately, I can just rebuild the index files and everything appears back to normal...but how could this have happened, and what are some preventative steps I can take to keep it from happening again?

Let me know, thanks.

QUOTE (ultramalcolm @ Aug 9 2006, 03:05 PM) *
Okay...so, my three MT 3.2 blogs just got hacked.

All three now read:

0wned by PSYCH@
Fuck israel. No waR.

Now, I don't think this was an ftp security breach, since all my other sites are fine. Only those powered by MT were affected.

Fortunately, I can just rebuild the index files and everything appears back to normal...but how could this have happened, and what are some preventative steps I can take to keep it from happening again?

Let me know, thanks.


I take it back...I think it was an FTP breach.

thanks
Twinmama
I just got nailed too. It seems to be an issue with permissions. I found this -

what's almost certainly happened is this:

A malicious script has been set loose on the webhosts server.
That script searches for files that it can write to.
Such files are usually blog files.
This is not MT hacking as much a combination of a webhost security and your file permissions.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.