One of my admin just sent me a message saying she'd seen additional staff added to the moderator list in the admin panel. I went and checked and I had two extra Admin with full permissions added as staff. No IP addresses available in their profiles...no posts made, nothing noted in the mod/admin logs etc. One account was added on the 3rd and another on the 4th. One of the users had "hack" in their username and email. How is this possible? Running 4.2.1 Have deleted the accounts now and have deleted my Install folder...how do I stop this happening again?
Hacked?
Collapse
X
-
You should probably check for a shell (a php file added to your webspace that lets a remote user perform all kinds of functions), review all of your plugins, and review all of your read/write permissions as well. The damage can be worse than you think.
Usually looking at the creation/modification dates can assist you in finding newly added files.Comment
Related Topics
Collapse
-
by texaserinHI.
I upgraded to 5.1.0 yesterday. Everything seems to work well except that when I make a post as an admin in a forum, it is automatically deleted. I can go back and undelete it, and everything...-
Channel: Support Issues & Questions
Fri 28 Mar '14, 9:09am -
Comment