<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xml:base="https://www.webmaster-forums.net/crss/node/1053533" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title></title>
    <link>https://www.webmaster-forums.net/crss/node/1053533</link>
    <description></description>
    <language>en</language>
          <item>
    <title>Ahh right .. OK, well, I do</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/php-website-has-been-hacked-please-advise#comment-1275328</link>
    <description> &lt;p&gt;Ahh right .. OK, well, I do use WiFi, but its private and secured.&lt;br /&gt;
I do use my main cPanel login for FTP, so next time I use my client, I&#039;m gonna check out the options. I just assumed the client would use the best option for me automatically...&lt;/p&gt;
&lt;p&gt;I&#039;ve been spending all my time trying to secure my PHP Files, it never occured to me that my FTP Client could be causing security holes...&lt;/p&gt;
&lt;p&gt;Thanks for the info, seems I&#039;m not as clued up as I liked to think I was...&lt;/p&gt;
 </description>
     <pubDate>Thu, 10 May 2012 21:12:35 +0000</pubDate>
 <dc:creator>DarkLight</dc:creator>
 <guid isPermaLink="false">comment 1275328 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>If you are using the main</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/php-website-has-been-hacked-please-advise#comment-1275326</link>
    <description> &lt;p&gt;If you are using the main account login (the one you use for your cpanel login) you should be able to do SFTP. If you are using a secondary FTP account (one that was created once logged into cpanel), then the best you can do is &quot;FTP with TLS/SSL&quot; (there are usually two options, I forget which one worked with my cpanel accounts.&lt;/p&gt;
&lt;p&gt;Normal FTP programs sent the password as plain text when logging in, so you definitely do not want to use regular FTP over public Wifi, as it can be sniffed, and at that point, it doesn&#039;t matter how strong of a password you use.&lt;/p&gt;
&lt;p&gt;Hopefully though you won&#039;t have any more issues. I know they can be a pain in the but to track down. Good luck!&lt;/p&gt;
&lt;p&gt;-Greg&lt;/p&gt;
 </description>
     <pubDate>Thu, 10 May 2012 18:45:26 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1275326 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>Ahh, I see :/ I guess I got a</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/php-website-has-been-hacked-please-advise#comment-1275318</link>
    <description> &lt;p&gt;Ahh, I see :/ I guess I got a lot of work to do then. I have already looked through the files, and everything is clean and as it should be. I already have almost all known security measures in place.&lt;/p&gt;
&lt;p&gt;sFTP? I&#039;m guessing thats SecureFTP? Requires HTTPS/SSL? I don&#039;t have that, but I do have strong passwords for FTP Accounts and cPanel.&lt;/p&gt;
&lt;p&gt;The team who hacked me are called DefCon, of that means anything, and as far as I can see, they havent done anything malicious, just uploaded a file.&lt;/p&gt;
&lt;p&gt;One thing I didnt do, is check the logs. If this happens again, I will be sure to do that. Its maybe too late now.&lt;/p&gt;
&lt;p&gt;Thanks for the info, really appreciated! &lt;img src=&quot;https://www.webmaster-forums.net/misc/smileys/smile.png&quot; title=&quot;Smiling&quot; alt=&quot;Smiling&quot; class=&quot;smiley-content&quot; /&gt;&lt;/p&gt;
 </description>
     <pubDate>Thu, 10 May 2012 11:40:42 +0000</pubDate>
 <dc:creator>DarkLight</dc:creator>
 <guid isPermaLink="false">comment 1275318 at https://www.webmaster-forums.net</guid>
  </item>
  <item>
    <title>It would really depend on</title>
    <link>https://www.webmaster-forums.net/web-programming-and-application-development/php-website-has-been-hacked-please-advise#comment-1275293</link>
    <description> &lt;p&gt;It would really depend on what type of site you have hosted, as well as what type of hosting environment.&lt;/p&gt;
&lt;p&gt;I do see you are using cPanel, which generally locks down accounts pretty good to prevent the issue of one user being able to write into another user.&lt;/p&gt;
&lt;p&gt;If it was my server or one I was maintaining, I would be checking the log files for the time period the the file was added, as well as log files for things such as FTP.&lt;/p&gt;
&lt;p&gt;Good practice would be to make sure you change the passwords ASAP to something strong, and never use regular FTP for transferring files, use SFTP instead.&lt;/p&gt;
&lt;p&gt;Also now that you have been hacked, go check EVERY FILE on the site. Myself I would look through the code of every file that was modified within a month of when you know that the site was hacked. Many times hackers will hide a hack script somewhere deep into a directory, naming it similar to something already there. With a script like that in place, they can pretty much do what they want with your site just from a browser window.&lt;/p&gt;
&lt;p&gt;-Greg&lt;/p&gt;
 </description>
     <pubDate>Thu, 10 May 2012 07:26:54 +0000</pubDate>
 <dc:creator>Greg K</dc:creator>
 <guid isPermaLink="false">comment 1275293 at https://www.webmaster-forums.net</guid>
  </item>
  </channel>
</rss>
