Elxis CMS Forum

Support => Security => Topic started by: mmarch on February 21, 2008, 10:50:04

Title: Problem with phishing - continuing
Post by: mmarch on February 21, 2008, 10:50:04
Hi everyone of Elxis community!!!

Today checked my error logs and found something interesting.
In previous topic i has a problem with phishing, after that i deleted my host account and reinstalled elxis again. I did it 4 days ago. My passw is new and verry hard, I didn't think that somebody can get acces to my account again. Of course Elxis defender and flood blocker are enabled. Today morning i installed akocomment bot and after problem with captcha (it's dos not appear in site) i checked error logs and found this error

[Wed Feb 20 22:46:49 2008] [error] [client 124.178.232.181] File does not exist: /home/sitename/public_html/includes/captcha/cgi/anz.com.au/inetbank/bankmain.asp/ANZ-Regional-Rural-Quarterly/e-online-banking/AuthServiceaction=presentLogin/udpate-infos-ANZ=user_cmdID12549JDk23/Bankmain.htm

what dos it mean??? How i can fix this problem?

Title: Re: Problem with phishing - continuing
Post by: Ivan Trebješanin on February 21, 2008, 11:57:49
Hi mmarch, here we go again... ;) You don't have to be afraid if someone is requesting file that don't exist anymore. As I told you, the same guys who hacked your box, did it to my client. Now, even months after I deleted every sign of them, I still find requests for deleted files. But, these are just REQUESTS! Important thing is that those files do not exist anymore.
Title: Re: Problem with phishing - continuing
Post by: mmarch on February 21, 2008, 12:05:13
yes of course you are a right, but i have question - from where this request came if i reinstalled fresh version???
Title: Re: Problem with phishing - continuing
Post by: Ivan Trebješanin on February 21, 2008, 12:27:31
When visitor comes to your site, all he does is making requests: this page, that page, this picture... So any visitor could request for /some_folder/ANZ/something
What is important is that his requests can't be fulfilled. I believe I have sent you some link for learning how hosting server work. Read it. ;)
Title: Re: Problem with phishing - continuing
Post by: mmarch on February 21, 2008, 12:38:50
In moment i have not a time i get your links, but i will read later.

And what about problems with captcha? Why captcha not working in akocomment ?