[TYPO3-english] Have I been hacked? Please help.

Andreas Becker ab.becker at web.de
Sat Mar 19 10:06:16 CET 2011


Hi Morton

That a site looks strange and that you can't login can have multiple
reasons.


   1. you are actually not loggin to your site but your apache is loading
   the default page with your domain and not the page you are actually calling
   ;-) >>> reboot apache

   2. You haven't been hacked but you have service providers which cache
   your content on a proxy , i.e. censorship, This happens quite often here in
   Thailand, than you could try to use ctrl F5 and reload your pages.

   3. You have been hacked as your database data has been exposed due to the
   fact that the default password hasn't been changed and there was still the
   security enable file active.
   Happend i.e. in 2008 Schaeuble, Schalke, UNESCO Bangkok, etc. but has
   been mad much more secure ever since. >>> Check which version of TYPO3 you
   are running and start reading the security bulletins and keep your system
   always up to date.

   4. check if you have setup your site in a secure way.
   http://secure.t3sec.info/tutorials/typo3/credentials-outside-of-webroot/

   5. update all extensions and your core system.


How to get access to the backend you can contact me via PM. IMHO it is not
good to discuss this here on the list as actually everyone can already read
how to get inside TYPO3 if the developers and site adminstrators don't take
at least common security measures into account.

Andi

On Sat, Mar 19, 2011 at 3:41 PM, Morten Kjems <mortenkjems at gmail.com> wrote:

> I am unable to login to the backend of one of my sites. None of the logins
> work.
>
> The mainpage looks wrong, no major errors but some weird additional content
> are displayed.
>
> Two questions.
>
> Have I been hacked?
>
> How do I get access to the backend?
>
> I do have access to the database and the files.
>
> please help me out.
>
> Thanks.
> _______________________________________________
> TYPO3-english mailing list
> TYPO3-english at lists.typo3.org
> http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-english
>


More information about the TYPO3-english mailing list