<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1029045" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1029045</link>
    <description></description>
    <language>en</language>
          <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170404</link>
    <description> &lt;p&gt;Difficult to get help when people try to help you by asking questions and you don&#039;t answer.&lt;/p&gt;
&lt;p&gt;Check your mysql database and see what is there. If there are any entries in there that use anything in the host field besides localhost, I would remove them or change the password. I would also change the root password as well. Might look at &lt;a href=&quot;http://dev.mysql.com/doc/mysql/en/security-against-attack.html&quot; class=&quot;bb-url&quot;&gt;this&lt;/a&gt; as well.&lt;/p&gt;
 </description>
     <pubDate>Sat, 30 Apr 2005 22:15:24 +0000</pubDate>
 <dc:creator>mairving</dc:creator>
 <guid isPermaLink="false">comment 1170404 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170393</link>
    <description> &lt;p&gt;Just because something is the latest version, doesn&#039;t mean that it&#039;s secure. It might be worth portscanning your server and seeing if you have any excess ports open and if you do get them locked down.&lt;/p&gt;
&lt;p&gt;I&#039;m not an expert on server security but I know for a fact locking down your server is the first step to security. Also, change all your passwords reguarlly to slow down their future atempts&lt;/p&gt;
 </description>
     <pubDate>Sat, 30 Apr 2005 17:14:42 +0000</pubDate>
 <dc:creator>andy206uk</dc:creator>
 <guid isPermaLink="false">comment 1170393 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>hey</title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170379</link>
    <description> &lt;p&gt;i have cpanel , and everything TO LATEST VERSION ,even the cpanel ...&lt;br /&gt;
I knew how he&#039;s hacking me , i have shell disbaled on all accounts , but still he&#039;s using mysql shell ! how can i stop that ?&lt;/p&gt;
 </description>
     <pubDate>Sat, 30 Apr 2005 04:38:29 +0000</pubDate>
 <dc:creator>_sam_</dc:creator>
 <guid isPermaLink="false">comment 1170379 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170293</link>
    <description> &lt;p&gt;Wait a minute, is the same server that you have listed as &quot;My server is secured !&quot; (see &lt;a href=&quot;http://www.webmaster-forums.net/showthread.php?t=29023&quot; class=&quot;bb-url&quot;&gt;http://www.webmaster-forums.net/showthread.php?t=29023&lt;/a&gt; )&lt;/p&gt;
&lt;p&gt;  Also mentioned in another post, not sure if it is the same server &quot;my site is phpnuke platinum !&quot; (see &lt;a href=&quot;http://www.webmaster-forums.net/showthread.php?t=29022&quot; class=&quot;bb-url&quot;&gt;http://www.webmaster-forums.net/showthread.php?t=29022&lt;/a&gt; ) This information may help others help you find the problem.&lt;/p&gt;
&lt;p&gt; If they are the same server, then I feel that you need to edit or delete your post advertising your server is secured until you can fix it.&lt;/p&gt;
&lt;p&gt;  -Greg&lt;/p&gt;
&lt;p&gt; PS. Assisin, I use PHP, so send me the info on the fix to this hack that  anyone can use to delete all my databases.&lt;/p&gt;
 </description>
     <pubDate>Thu, 28 Apr 2005 18:17:31 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1170293 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170287</link>
    <description> &lt;p&gt;Really would need more info to give a good guess.&lt;/p&gt;
&lt;p&gt;Is it a shared server? You are buying hosting from someone else. Then you should check with your host and let them look in their logfiles.&lt;/p&gt;
&lt;p&gt;Is it a dedicated server? Is everything fully patched?&lt;/p&gt;
&lt;p&gt;What OS are you running?&lt;/p&gt;
&lt;p&gt;Are you using a CMS or other PHP/Perl script? Is it the latest version?&lt;/p&gt;
&lt;blockquote class=&quot;bb-quote-body&quot;&gt;&lt;p&gt;&lt;strong&gt;Assassin wrote:&lt;/strong&gt; If you have PHP enabled, there is a simple hack that can mess up all of your databases. I don&#039;t know the fix off the top of my head, but I&#039;ll get it to you if this is a possible problem. Let me know if it&#039;s possible.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;There is no hack that has anything to do with the current versions of PHP. There are certainly cross-scripting and sql injection vulnerabilities in scripts but these are readily identifiable and fixable.&lt;/p&gt;
 </description>
     <pubDate>Thu, 28 Apr 2005 17:55:50 +0000</pubDate>
 <dc:creator>mairving</dc:creator>
 <guid isPermaLink="false">comment 1170287 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170229</link>
    <description> &lt;p&gt;If you have PHP enabled, there is a simple hack that can mess up all of your databases. I don&#039;t know the fix off the top of my head, but I&#039;ll get it to you if this is a possible problem. Let me know if it&#039;s possible.&lt;/p&gt;
 </description>
     <pubDate>Wed, 27 Apr 2005 22:53:59 +0000</pubDate>
 <dc:creator>Assassin</dc:creator>
 <guid isPermaLink="false">comment 1170229 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title></title>
    <link>https://www.webmaster-forums.net/server-management/bad-thingy#comment-1170203</link>
    <description> &lt;p&gt;are you running phpbb, pukenuke or any of the other programs via cpanel?&lt;br /&gt;
if so are they updated to latest secure versions?&lt;br /&gt;
do your logs show anything?&lt;br /&gt;
do you run a cronjob?&lt;br /&gt;
Is it your own server or a hosts server? are there any .exe&#039;s or files in the root directory that shouldn;t be there (a worm or virus, trojan etc)&lt;/p&gt;
 </description>
     <pubDate>Wed, 27 Apr 2005 10:27:06 +0000</pubDate>
 <dc:creator>Busy</dc:creator>
 <guid isPermaLink="false">comment 1170203 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
