close ad
 
Important WebAssist Announcement
open ad
View Menu

Technical Support Forums

Free, outstanding support from WebAssist and your colleagues

rating

Has anyone had their CMS site hacked?

Thread begun 11/03/2023 1:32 pm by LWag48648773 | Last modified 11/04/2023 6:46 am by LWag48648773 | 270 views | 6 replies |

LWag48648773

Has anyone had their CMS site hacked?

Just happened today. Definitely got in through the CMS. Sorry I have to ask this now at such a bad time but others need to know if this is a huge problem. Hoping it's not. Any thoughts would be helpful.
Thank you

Sign in to reply to this post

PatriceWebAssist

Please add details. What is the url?

Sign in to reply to this post

LWag48648773

I took the site down temporarily. I was just curious if anyone else had issues. It seemed somewhat coincidentally so soon after Ray isn't here to help with things like this. But maybe that's all in my imagination.

Sign in to reply to this post

PatriceWebAssist

If you want to upload again, share URL, I am guessing the experienced peeps on this list can track down issues. There is an amazing list of knowledge here.

Sign in to reply to this post

LWag48648773

Thank you very much Patrice. I'm keeping the site down for the weekend. I made some screenshots of the one page before I started fixing. The last shot is when I was logged into CMS. My first thought was hacker got in through CMS code but now I'm wondering if he got in through database.

If anyone has seen anything like this before (attached) or can lend advice in any way, I am most grateful. Thank you, Laura

Attached Files
hacker.pdf
Sign in to reply to this post

Mags

I haven't seen this happen before, but the first thing that springs to mind is have you upgraded the site to mySQLi? If you're still using mySQL on php5 or older, it's much more susceptible to hacking. You should be on at least php7.4 but preferably php8 and definitely using mySQLi.

Download the free mySQLi tools, install the latest version of DataBridge 2 and then open any Recordsets, Insert, Update, and Delete Server behaviors on the page and switch them to the MySQLi connection. Once you click OK with a MySQLi connection, then the code is updated to MySQLi.

You can also download a beta version of PowerCMS here which updates to myMSQLi: https://www.webassist.com/PowerCMS.zip - there are further details in this thread: https://www.webassist.com/forums/posts.php?id=45570. It's a couple of years since I upgraded my PowerCMS sites to mySQLi /php7 and I can't remember if I had any issues with it, but if you hit any snags then just add to this post and I'll try to help!

Sign in to reply to this post

LWag48648773

Thank you so much but no - that's not it. I've been up-to-date all along. I think it was the way I had my databases setup. Not very secure. I changed users for each of them now and each user has a generated password. I'm sure hoping that will keep them out of my other databases and CMS.

Sign in to reply to this post

Build websites with a little help from your friends

Your friends over here at WebAssist! These Dreamweaver extensions will assist you in building unlimited, custom websites.

Build websites from already-built web applications

These out-of-the-box solutions provide you proven, tested applications that can be up and running now.  Build a store, a gallery, or a web-based email solution.

Want your website pre-built and hosted?

Close Windowclose

Rate your experience or provide feedback on this page

Account or customer service questions?
Please user our contact form.

Need technical support?
Please visit support to ask a question

Content

rating

Layout

rating

Ease of use

rating

security code refresh image

We do not respond to comments submitted from this page directly, but we do read and analyze any feedback and will use it to help make your experience better in the future.

Close Windowclose

We were unable to retrieve the attached file

Close Windowclose

Attach and remove files

add attachmentAdd attachment
Close Windowclose

Enter the URL you would like to link to in your post

Close Windowclose

This is how you use right click RTF editing

Enable right click RTF editing option allows you to add html markup into your tutorial such as images, bulleted lists, files and more...

-- click to close --

Uploading file...