Results 1 to 4 of 4

Site hacked

This is a discussion on Site hacked within the Troubleshooting forums, part of the vBSEO Google/Yahoo Sitemap category; Hi. I would appreciate some help and advice. My site has been hacked twice in the last few days and ...

  1. #1
    Member
    Real Name
    Dave
    Join Date
    Mar 2009
    Posts
    37
    Liked
    1 times

    Site hacked

    Hi. I would appreciate some help and advice.
    My site has been hacked twice in the last few days and each time it has been by placing a php file in the vbSEO_sitemap folder. This folder is chmoded to 777 as per the installation instructions.
    I realise that it needs to have write access for the sitemap to be written but how on earth do I stop a hacker adding php files when that folder is wide open like that?

    Both vB, vBSEO and vBSEO Sitemap are at the very latest versions on your site.

    Any ideas and help?

  2. #2
    vBSEO Staff Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,393
    Liked
    411 times
    Blog Entries
    1
    Hello Dave,

    The only one folder that needs to be chmoded to 777 is the "data/" folder (inside vbseo_sitemap/ folder), *not* the "vbseo_sitemap/" folder (it needs to keep permissions set to 755).
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  3. #3
    Member
    Real Name
    Dave
    Join Date
    Mar 2009
    Posts
    37
    Liked
    1 times
    Sorry yes as soon as I posted that I wonderd this... I now can't be sure whether I did set that properly. So if I have the .htaccess file there and only set chmod 777 on the data directory it should be perfectly secure?

  4. #4
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    The htaccess file in the writable file stops direct script execution. Make sure it is in the /data/ folder correctly.

    If you are not on apache, you will need to convert those rules to your web server system.

Similar Threads

  1. Got hacked, need some help
    By ludachris in forum Troubleshooting
    Replies: 2
    Last Post: 12-02-2009, 07:35 PM
  2. I was hacked
    By goranbaxy in forum General Discussion
    Replies: 14
    Last Post: 07-31-2008, 03:15 AM
  3. hacked??
    By genusis in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 09-13-2007, 05:11 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •