Recent Topics

1 Oct 09, 2009 06:59    

My b2evolution Version: Not Entered

Got a note from google today saying I was violating TOS due to hidden text on my site and they are removing me from their index. Apparently someone got past my admittedly lame security and put in some hidden text.

http://www.yourwildchild.com -> view source -> very bottom of page.

The text is outside the </html> tag. Have no idea which file to look in to make this fix beyond the index.php and the index.main.php file from my skin.

Any ideas?

2 Oct 09, 2009 15:52

That is quite possibly the limit of damage, but you might want to use your FTP program to compare date stamps on all files in the /skins/ folder including all files in any skins you have in the /skins/ folder.

Alternatively, and much easier, delete your entire /skins/ folder from your server and upload clean copies from your local backup copies. You do have backup copies of all the files I trust?

By the way consider the same for all files in your installation's root directory. Oh and any directories you've got opened up to 777 if there are any. /media/ is a good place to assume some evil has been done, though I don't think anything bad in /media/ can do damage to what gets displayed by index.php or a stub file.

3 Oct 09, 2009 17:16

Thanks. Actually they modified my index.php and blogX.php where X= valid blog entries. Also modified /htsrv/trackback.php and may have added a file called .ftpquota

These files all had 755 permissions. Don't they need that to be able to execute the blog code or can I clamp them down tighter? Not sure how they got access to the files when there was only write access for the owner.

Thanks again,

Henry

4 Oct 09, 2009 17:23

I've no idea how folks get in and do bad things other than my own experience: 777 on /media/ opens a door to anyone else on the same shared server.

Password got out or was guessable maybe?

Oh ftpquota might be a real file. I've got copies of that on some servers I get to play with, but not all of them. Dunno what it is or does, but I'd bet ya half a loaf of slightly stale bread google does :)

5 Oct 11, 2009 20:42

Thanks EdB,

I ended up re-installing (and uprading to 2.7 at the same time). The permissions on those files by default is 644 so I'll just keep them that way.

The real pain is that I got temporarily dropped from Google index for "violating" TOS. Could have been worse though.

Thanks again,

H.


Form is loading...