Toplist input path being hijacked

Our support will answer all your general questions here.

Moderator: Rock

Post Reply
johnp
Posts: 1
Joined: Wed Jun 10, 2009 9:37 pm

Toplist input path being hijacked

Post by johnp »

It looks like some hacker was able to edit the input path for the toplist. The input path was changed to "tmp/top"
The hacker seems to have created this new file in the "tmp" directory, called it "top" and changed the input path for the toplist to that file. This new file in "tmp/top" was created/is owned by user "www-data"

This has been going on for the past month. I keep trying new things to stop this, but it comes back. I changed the input path back to the real one, then I reset the TE admin password. Everything was fine for a few days, and then again last night the input path was changed. So I'm not sure how to fix this. Nothing else on my server is compromised, just the toplist. The hacker inserts a malicious javascript in the toplist file that causes many problems...

Any help on how to stop this would be appreciated.

Regards,
John
texpert
Site Admin
Posts: 719
Joined: Sat Mar 14, 2009 5:54 pm

Re: Toplist input path being hijacked

Post by texpert »

Hello johnp,
can you please contact me on ICQ?

My ICQ No.: 374821862


Best regards,
Alex
Post Reply