for people on Servage.net

Vaska A / 2009-04-12 16:42:35   

Turn ON the geoip security and bind the login to your country and IP range. There is info about this on their site.

We too were hacked recently - because they actually logged in on an FTP account.

Check your FTP accounts and delete any that you did not create.

Always backup the files on your site periodically.

We do not recommend this host any more.

lauraphilpot / 2009-04-12 17:54:03   

help. I'm on servage.net. i have contacted them and they said:

'Hello neil,

When I visited your site, it showed "Fatal error: Cannot redeclare get_counter() (previously declared in /mounted-storage/home95b/sub002/sc50334-PJGI/www/index.php:1) in /mounted-storage/home95b/sub002/sc50334-PJGI/www/index.php on line 1" which was absolutely scripting error.

You may re-install your script - we do not provide support third party script installation.

I am not sure why your script designer told you that it had been hacked.

Please note that an account can easily be exploited due to poor script/back dated script. Poor file permission or poor password may be another reason.

Regarding backup, We do backup our systems against data loss in cases of for instance hardware failure. However, we are unfortunately not able to offer a restore of single files or accounts from a past date. We therefore recommend that you always make your own backup for both web site content and database.

Thanks for your understanding!

Kind Regards
Sam, Support
Servage Hosting'

my website is www.neilpreston.co.uk

I would just like to know simply how to fix this.

thank you

Neil Preston

Vaska A / 2009-04-12 18:16:05   

Yes, of course it's our fault (not really). Which is why they had to disable our FTP account when hackers managed to login in on it (because the hackers found a fault in their system). Which is why tons of sites on the same server us as that don't even use cms' have been hacked as well.

It's too complicated to simply fix...it's really not easy. You have to find all files throughout your system with the word 'index' in it and take out the hack...one by one...one at a time.

Your database is fine...so delete all your files and upload new files...be sure to keep the database connection information so you can reproduce the connection file.

You will need to work all your customizations back into things...

And be sure to backup your files so restoring after this kind of thing is nearly automatic.

lauraphilpot / 2009-04-12 18:20:23   

ok thanks for your reply.
i kind of get what your saying apart from

'be sure to keep the database connection information so you can reproduce the connection file.'

what does that bit mean?

also is there a simple way to delete all files?
thanks Neil

Vaska A / 2009-04-12 18:25:45   

Yes, deleting the files is easy...your ftp app does that.

Back thing up first...even if they are hacked...

The file at /ndxz-studio/config/config.php is your connection info. When you are done doing whatever with your files you will want the info from this file to create a new one (or you can reupload it to the right place as it wasn't hacked).

And then you are back in action.

THEN, backup a clean set of files just in case. This problem has been ongoing for months and it stopped...I had some reports the day this happened from other people that they were getting warning notes that people were trying to login to their accounts. The hackers, even with our obscure password, managed to login on our account...

The geoip tools have been helpful but we didn't have it bound to our ip addresses - now we do.

There is a reason why they are no longer mentioned in the Useful Threads post...

lauraphilpot / 2009-04-12 18:28:55   

i'm sorry i don't get the top bit, what do i need to re upload? i'm so frustrated it took me ages to get this right.

Neil

Vaska A / 2009-04-12 18:40:28   

The Indexhibit system files.

I believe you can set permissions to 755 on folders as well and you can still upload. But, if hackers are logging in via ftp what can you really do...nothing.

lauraphilpot / 2009-04-12 18:48:26   

ok i really need an idiots guide.

i deleted the gimgs file.
what other files need to go?

which ones do i need to re-install?

thanks for your help Vaska, top man

Neil

Vaska A / 2009-04-12 19:01:54   

THE SYSTEM FILES!

/ndxz-studio/

NOT THE FILES AND GIMGS FOLDERS!

You should just start over now...you've deleted your images.

lauraphilpot / 2009-04-12 19:03:50   

shit.
how do i start over?
this is fucked.

lauraphilpot / 2009-04-12 19:59:28   

my site still isn't working.
how do i make the message go away?

Neil

Vaska A / 2009-04-12 20:14:06   

Reupload the root index.php file.

lauraphilpot / 2009-04-12 20:17:03   

ok man i'll give it a go now

lauraphilpot / 2009-04-12 20:29:48   

i'll be honest I can't find it

Eloisa A / 2009-04-12 21:34:17   

The index.php file that is inside the indexhibit folder when you download it to your computer > you should put it in the root folder of your site

You have to read more carefully!

lauraphilpot / 2009-04-13 14:46:46   

ok. thank you for your advice.

I re-uploaded the index.php file through the website builder that servage offer. I now have a different message on my site.

Warning: require_once(ndxz-studio/defaults.php) [function.require-once]: failed to open stream: No such file or directory in /mounted-storage/home95b/sub002/sc50334-PJGI/www/index.php on line 9

Fatal error: require_once() [function.require]: Failed opening required 'ndxz-studio/defaults.php' (include_path='.:/usr/share/php5/') in /mounted-storage/home95b/sub002/sc50334-PJGI/www/index.php on line 9

what does this all mean? I remember i deleted 2 files named 'gimgs' which I created again and another one titled 'files'. does this affect anything?

help please.

Neil

Vaska A / 2009-04-13 15:35:05   

It says you are missing some files...it's looking for...

/ndxz-studio/defaults.php

You haven't reuploaded everything.

lauraphilpot / 2009-04-13 15:46:14   

I've uploaded that file now, it still says the same thing

neil

lauraphilpot / 2009-04-13 15:51:41   

ok it's changed it now says

no direct script access allowed

suggestions?

neil

lauraphilpot / 2009-04-13 16:00:35   

it's changed again. it now says

* Built with Indexhibit

am i any closer?

neil

www.neilpreston.co.uk

lauraphilpot / 2009-04-13 18:38:08   

i have uploaded the index.php and the common.php.

the message on my site is now unreadable and i can no longer login through indexhibit.

help!

Neil

Vaska A / 2009-04-13 19:38:54   

Send me your ftp login and I'll take a look at things...

contact [at] indexhibit [dot] org

lauraphilpot / 2009-04-13 20:02:20   

i've emailed you

cheers for this

lauraphilpot / 2009-04-14 08:16:38   

Vaska did you get a chance to look at it?

thanks

Neil

Vaska A / 2009-04-14 10:16:05   

Yes...but you haven't even uploaded Indexhibit.

You know...I rarely ever advertise this around here...but we do have a paid installation service.

You have to start over now...you can use the How to install instructions...but since you already had an installation you will need to manually recreated the config.php file with your database connection info instead of running through things.

lauraphilpot / 2009-04-14 15:55:50   

Vaska

thanks for your time.
I wiped everything and reuploaded the file through cyberduck becuase I couldn't work out how to do it through servage.

It's all there and I've changed the 3 files mentioned permissions to 777.

i type in

http://www.neilpreston.co.uk/ndxz-studio/install.php

and it says

'Not Found     

The requested URL was not found on this server.'

which bit am i doing wrong?

thanks for your help, it is much appreciated.

Neil

lauraphilpot / 2009-04-14 19:32:31   

i'm still lost

any help appreciated

neil

lauraphilpot / 2009-04-14 20:14:55   

Vaska.

i'm really struggling here.
everything is in there, i've checked and double checked.
all the permissions are correct.
what am i doing wrong?
i've been trying to fix this for 3 days

please help man

Neil

lauraphilpot / 2009-04-14 20:19:14   

it now says

Index of /

* indexhibitv070e 2/

Apache Server at neilpreston.co.uk Port 80

when you click on the link it says

database not installed

am I any closer?

Neil

Eloisa A / 2009-04-14 20:54:44   

Neil, are you really following the steps in the installation guide for dummies?

Specifically: "you drag the contents of the indexhibit folder (from your computer) into the root folder of your server."

I know all of these things can sound difficult, but you NEED to become a little more autonomous if you want to learn. Clearly you haven't uploaded the folder in the right place, and it's your job to figure out what you've done with it / where you've put it. Good luck.

lauraphilpot / 2009-04-14 20:56:39   

ok. i;m on the config.php iv'e changed it to;

lauraphilpot / 2009-04-14 20:59:17   

$indx['db']         = 'neilpreston1';
$indx['user']         = 'neilpreston1';
$indx['pass']         = '********';
$indx['host']         = 'servage.net';
$indx['sql']        = 'mysql1067.servage.net';

is that right?

please help

lauraphilpot / 2009-04-14 21:01:00   

i have dragged it in to the folder called 'www' which i was told is the root folder

Eloisa A / 2009-04-14 21:05:05   

Then why is there a folder in your root called indexhibitv070e?

lauraphilpot / 2009-04-14 21:11:27   

i've moved the folder over.
and changed the permissions.
still the install page won't show up.
i've tried to be autonomous, but being sat here for three days trying to figure out why you're website is fucked over is hard.

Neil

Eloisa A / 2009-04-14 21:14:53   

You do not need to move the folder over, just the contents.

lauraphilpot / 2009-04-14 21:16:24   

ok well everything is definitely in the root folder. still no joy.

Eloisa A / 2009-04-14 21:22:13   

Do you have a ndxz-studio folder in it? because this doesn't work, and it should: http://www.neilpreston.co.uk/ndxz-studio/install.php

lauraphilpot / 2009-04-14 21:25:00   

theres two files in the root folder.

www
indexhibitv070e2

there is a ndxz-studio file in the indexhibitv070e2 file.

neil

Eloisa A / 2009-04-14 21:34:47   
So you didn\'t drag the contents, but the folder (my post 4 posts above). You need to drag the contents into the root folder, not the folder.
lauraphilpot / 2009-04-14 21:40:22   

ok, i appreciate i read that wrong, i have dragged the contents over now. in the root folder it now reads

files
htcaccess
index.php
ndxz-studio

i have sorted the permisions.
http://www.neilpreston.co.uk/ndxz-studio/install.php

this still doesn't work

Neil

Eloisa A / 2009-04-14 21:52:29   

This says there's nothing in your root folder.

lauraphilpot / 2009-04-14 22:22:13   

i don't understand. there are no files in my filemanger.
do i need to create one and put the indexhibit stuff in there? or do I (as i have done) just put the indexhibit stuff in the main page ( on the main page when i go to upload something to it it says /(root folder) )

what am i missing? i'm sorry to be such a hassle

neil

Eloisa A / 2009-04-14 22:28:19   

You need to put the contents of the indexhibit folder inside your root folder.

lauraphilpot / 2009-04-14 22:31:02   

i have done

my root folder reads

files
ndxz-studio
htaccess

lauraphilpot / 2009-04-14 22:53:57   

the folder www is referred to as document root.
should i upload indexhibit up to that folder?

lauraphilpot / 2009-04-14 22:58:26   

I'VE DONE IT!
ITS UP
IT WORKS!!!

THANK YOU!

aliocha / 2010-04-04 19:12:44   

Ahem, Neil you should really consider removing your "install.php" file.

This thread has been closed, thank you.