Both my sites were hacked on Mon 19th. They were both running
Drupal version 6.16
Most modules updated.
Apache version2.2.9 (Unix) PHP version5.2.6
I do use FTP to upload modules sometimes.
InMotion Hosting is my hosting company
The permissions are either 755 or 644 in the Drupal directory.
My webhosting company was able to get the other site up and running but my main product site wasn't able to be debugged.
Problems: I cant login or I get a 404 error. If I click on any link on the site to go to the catalog for example I get a 404 not found. I don't know where or what to look for to find what was altered.
I went and deleted all the files for the site and the uploaded my backups and I am still getting the same problems.
Don't know what to do.
Comments
If you have removed the files
If you have removed the files and cleared the DB and re-installed and you are still getting the issue its highly unlikely this is hacking. Might want to chat to your webhost company and see if every thing is fine on their end.
Hi Sam, I sent them a new
Hi Sam,
I sent them a new email. The webhosting company told me on the 19th that the sites had been compromised. They wouldn't give me details about how/when etc...
My hosting company is saying
My hosting company is saying that everything is fine on their end. I am not sure what to do.
When I click the links I keep getting:
Not Found
The requested URL /node/ was not found on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
What do I do?
Check check ownership and
Check check ownership and group privileges on your files if you restored as root.
Hello Banthm, Thanks for your
Hello Banthm,
Thanks for your response.
When you say check ownership and group privileges, how and where do I do this?
Thanks.
Your .htaccess file might not
Your .htaccess file might not be right. You mention clicking on the links, so I assume the home page is OK. Try navigating to pages as if clean URLs were disabled; if the pages do, indeed, work (likely), check the .htaccess file to see if the directory is set correctly.
Just my $0.02. Good luck!
P.S. - In my experience, the #1 reason for sites being hacked is usage of an obvious master login password.
Thank you bcobin. Yes, the
Thank you bcobin.
Yes, the homepage displays perfectly.
How do I go to the pages "if clean urls were disabled"?
If I view the .htaccess file - how do I check to see if the directory is set correctly?
I changed all my passwords and will do so every few months. :)
Thank you for the tips.
What modules do you use ?
Do you use any untested modules ?
I had once a strange issues with combination of Strongarm and Spaces modules in Betas. When used with Pathauto they ( i bet Spaces did ) broke aliased links and allowed me only to navigate to '/node/[blabla]' version of the content.
( In fact i couldn't navigate to anything at all because of use of Globalredirect module ;) )
Hello GrzegorzNowak, I don't
Hello GrzegorzNowak,
I don't think I am using any untested modules. I just have the basic Drupal installed, along with the ubercart modules.
I tried this
as found here: http://drupal.org/node/228462
I put this in for my website and the page showed up. http://www.example.com/index.php?q=user I was able to login, but the page won't show. So it shows me as logged in.
Then I tried this: Ensure that mod_rewrite is enabled
Navigate to phpinfo.php in a browser like this: http://www.example.com/phpinfo.php - On that page, look for a section called "Loaded Modules" and check that mod_rewrite is included. If not, mod_rewrite is not being loaded by apache and will need to be enabled. The process will be different depending on the server platform and apache build. Keep the phpinfo.php file for now - it will be helpful later.
I did this and all the php info showed up, but I don't see mod rewrite. What do I do to get mod rewrite installed?
I tried this step: Ensure that Drupal's .htaccess file is being used
Once it's been confirmed that mod_rewrite is enabled, double check that drupal's .htaccess file is in the site's root, and that it is working. Confirm that .htaccess is enabled by temporarily replacing Drupal's .htaccess file. Make a backup of the existing .htaccess and create one like this...
DirectoryIndex phpinfo.php
Now try the site URL without specifing a page or file in a web browser: http://www.example.com/. If you see PHP's phpinfo dump, the .htaccess file worked and you can restore the old one. If not, the server may not be allowing .htaccess overrides for your site.
This didn't work for me. The site displayed normally. I didn't see the info php dump.
...
First, your host says your site was hacked but won't say how? This seems to me that they were hacked not you, you were merely a victim.
Drupal will intercept URL's. From your description you seem to have your site up? So,
1. Is your site up?
if it is, good.
if it isn't see if you can restore it to a local copy using xammp, mamp or other local webserver config to make sure your backups are good. Also troubleshooting locally may be a bit faster.
2. It is up but you cannot login because clean url's is not working?
there is a page with lots of comments for various environments here
here is a link to disable clean url's from the db or settings.php
3. If you can log into your site and create content, then you can enable the php module and just make a php type content page for the phpinfo script.
Best of luck
-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide
Thank you Steven
No, they won't tell me when or how. I would at least like to know how so I can prevent it.
1. The site is up and the front page looks perfect.
2. I can login by using htttp://website.com etc... but the page won't display. It is only when I go to the main website page that it shows me as logged in.
Thanks for the links I will look at them.
When you say this: "then you can enable the php module and just make a php type content page for the phpinfo script"
Are you referring to the mod rewrite module? My hosting company just sent me an email saying that they turned it on.
Thanks much...
Disabling clean urls worked!
Now what do I do? Can I re enable them at some point?
THANK YOU THANK YOU ALL SO MUCH!
..
Now you have to do the dance to get the mod_rewrite working. There is a link above in my earlier response. So much will depend on your host provider and setup.
I will also suggest getting a local test environment and doing periodic restores from your production sites.
Oh, also, if your site was truly hacked, then you will need to change a lot of passwords.
-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide
I think I was posting as you were posting
I didn't see your post. Sorry.
The site is fully functional right now. Everything is working. I did change passwords and I can change them again.
Should i just leave the modrewrite on and the clean urls disabled?
Thanks
...
mod_rewrite isn't the problem. You just need it for clean url's to work. By all means, return your site to full functionality.
-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide
Thanks everyone
I am still working on getting the clean urls working again.
Thanks everyone for all the input.
Sound to me is more of the
Sound to me is more of the hosting problem causing the problem, in long run is better to move to a reliable hosting company that support drupal setting.
Hello Space, Everyone keeps
Hello Space,
Everyone keeps saying this - even people who know less than I do about sites. :) The thing is I have paid so far in advance for my hosting plan and things are tight right now. And I am afraid of choosing a bad hosting company. This is my second hosting company and my first one wouldn't allow me to cancel and that drug on for months with them charging me after I tried to cancel and move on etc..
I have installed mollum, bad behavior etc on all my sites - that I can. I look at the stats daily and I get something like 40 attempts in 6 days. I don't know if this is normal or what, but it is distressing.
Last week I was working on my other website, which was easier to restore than this one, and I was being hacked at the same time I was working on the site! I couldn't believe it! I immediately called my hosting company and they said yes...at that exact moment I was being hacked. I was so terrified.
They had me on hold while the tech guy did something and he said he deleted the malicious code, but no one can tell me how these guys are doing this. He told me the only way he can tell me who is if they download something and then upload it - then they would have their ip address. Otherwise they can't tell.
FTP client infected ?
My co-worker had once Total Commander infected with some kind of malicious software that was infecting all the index.php and index.thml files when he was FTP connected. Maybe something like that was your "hacker" ?
Not a single hosting company could probably prevent from this :/
One has to be careful 101% of the time.
Hello Grzegorz I am not sure.
Hello Grzegorz
I am not sure. I have changed everything and will try to do so often. I use Fetch as an FTP client. I am hoping that it is not infected.
.htaccess
Check if .htaccess is still there (in a root directory).
If so, make a backup and try to replace it with orginal file.
Ok thanks for the tip. I
Ok thanks for the tip. I will try this as well.
Thank you All So Much
I really appreciate all the help. I finally got the clean URLS to work! I appreciate all the suggestions, tips, links and info that helped me to get my site back to normal!