Welcome, Guest. Please login or register.
Did you miss your activation email?


Login with username, password and session length

Search

 
Advanced search

8043 Posts in 1856 Topics- by 2099 Members - Latest Member: roi
Pages: [1] 2   Go Down
Print
Author Topic: hacked...need help  (Read 727 times)
0 Members and 1 Guest are viewing this topic.
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« on: July 17, 2004, 09:29:00 PM »

I just discovered that my site using Calendar Script was apparently hacked via the security leak in the script. I've read the thread at http://www.calendarscript.com/support/forum/Forum3/HTML/000539.html  but I'm at a loss how to proceed. Reading the calendar.pl and calendar_admin.pl text does NOT tell me what version I'm running and I can't bring anything up. I'm nearly certain I paid for the upgraded version for this client some time ago but I'll be darn if I have that info. The date on the file is 5-17-2000 which is a long time ago.

QUESTIONS: Should I download the newest full version and  install it or the upgrade and install it instead? And will I loose all the calendar entries? Is there a way to preserve them? I would greatly appreciate any/all help. I'm desperate to fix this.

To answer the questions: This is on a Linux server. I'm on a Windows XP system using MSIE 6. When I tried to run the debug.pl I got an Internal Server Error. I don't have the server logs but this script has been working perfectly for a long time and nothing's been changed except this hack. My host (Page-Zone)is sure the site was hacked based on the fact that the index file was replaced with this message "bloodbr - the dark side of the linux - shoutz: ladeira" and the only only problem on the site is that the calendar will no longer come up (get internal error message). He said to change the password but I can't access admin or anything else.

I'm going to try to email this to Matt directly but it sounds like he's not always available via email. I'm hoping he'll at least have a record of when I purchased and what version.

Thanks!
Sheila Hoffman

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #1 on: July 17, 2004, 10:54:00 PM »

UPDATE: Just checked with Pay Pal and found out I'm definitely using the newest version of the software. And per the thread cited below there's not suppose to be a cfg file...but there is one.

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #2 on: July 18, 2004, 01:59:00 AM »

** Reading the calendar.pl and calendar_admin.pl text does NOT tell me what version I'm running **

It should right towards the top (see the following examples). CalendarScript version 2 didn't have a version # listed for the administration script. I don't know about just the calendar script.    

quote:
# CalendarScript
# Version: 3.1
#
# Copyright 2001 Scott
# htp://ww.CalendarScript.com/

# CalendarScript
# Version: 3.2
#
# Copyright 2001,2002 Scott
# htp://ww.CalendarScript.com/


** The date on the file is 5-17-2000 which is a long time ago. **

According to the CalendarScript History version 3 didn't come out until Nov. 2001! So you're definitely not using even close to a current version.

BTW. I believe CalendarScript version 2 was freeware and not shareware like the current versions are.

** Just checked with Pay Pal ... **

How would they know??

** Should I download the newest full version and install it or the upgrade and install it instead? **

It depends on what version you're upgrading from. IF you upload a full version, you'll likely loose any events already on the calendar.

JFYI

Dan O.


[This message has been edited by DanO (edited July 18, 2004).]

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #3 on: July 18, 2004, 09:52:00 AM »

I paid for my copy of the script via PayPal and so I have the date I sent Matt the money for the upgraded version. I'm guessing the files I was looking at were just the older version. But I had the new version installed. I'm DEFINITELY using the newest version.

So I'm probably going to just reinstall the full script later today or tomorrow. IF there's anyway to retain the current calendar entries it would sure be helpful to know before I do that.

Thanks,
Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #4 on: July 18, 2004, 01:52:00 PM »

** IF there's anyway to retain the current calendar entries it would sure be helpful to know **

Use the upgrades.

BTW. When upgrading, each of the required upgrades will need to be installed one at a time depending on the CalendarScript version in use. For example, if version 3.0 is installed, you'll need to install the 3.1 upgrade, then the 3.2 upgrade, then the 3.21 upgrade.

But being that you say the files currently in use are dated 5-17-2000, I suspect that you don't have any of the relatively current 3+ CalendarScript versions installed in which case there is no upgrade to the current version. A whole new installation will be required.

** I paid for my copy of the script via PayPal and so I have the date I sent Matt the money for the upgraded version. **

Maybe you didn't install it or you installed it elsewhere? BTW. Each domain the script is used on needs a separate license from Matt.

Dan O.

------------------

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #5 on: July 18, 2004, 02:56:00 PM »

Dan:

I only use the script on ONE site. I definitely installed it when I paid for it. The date I was referring to was a file on my hard drive not the server. Here's exactly what my PayPal receipt to Matt says:

Item Amount:  $50.00 USD
Item Title:   CalendarScript 3.2 Non-Profit License  
Date:   Dec. 4, 2002  

So please forget about the old version info. Since I have 3.2 installed I'm assuming I can download the full install of 3.21 and install it OVER what's there? And will THAT retain my data? I'm unclear from what you did say what exactly I need to do ...

quote:
When upgrading, each of the required upgrades will need to be installed one at a time depending on the CalendarScript version in use. For example, if version 3.0 is installed, you'll need to install the 3.1 upgrade, then the 3.2 upgrade, then the 3.21 upgrade.

thanks again for taking time to respond.
Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #6 on: July 18, 2004, 04:04:00 PM »

** Since I have 3.2 installed I'm assuming I can download the full install of 3.21 and install it OVER what's there? **

Yes, although there may be a couple of other files which are needed from the full version or to be edited as described at the previous forum message "Error: Template File Does Not Exist when Adding Event" (unless Matt has added them to the upgrade archive by now).

** And will THAT retain my data? **

Yes.

Dan O.

------------------

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #7 on: July 18, 2004, 05:16:00 PM »

Bless you Dan.

NOW... on a related note... IS there in fact a security vulnerability in the script? Was it in version 3.2 but fixed in 3.2.1? If there's NOT, I don't know how I got hacked. If there IS, then I'm not sure I WANT to reinstall the script at all!

Thoughts?
Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #8 on: July 18, 2004, 06:06:00 PM »

** Was it in version 3.2 but fixed in 3.21? **

From the CalendarScript History:

quote:
=========================
02/28/04 - 3.21 Released
=========================
Bug Fixes:
* Patch for potential security vulnerability which could allow malicious users to execute commands on the server
* Patch for infrequent newline problem which caused events files to become corrupt
Dan O.

------------------

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #9 on: July 19, 2004, 04:35:00 PM »

Dan:

Rather than start a new thread I thought I'd continue here. I downloaded the full 3.2.1, unzipped, modified base, FTP'd, CHMOD'd. I can get into calendar admin so I think I did everything correctly. However, I'm still not getting into the calendar. I know it all went up in ASCII. I've CHMOD'd calendar.pl & calendar_admin.pl to 755 and everything else to 777. I ran the debug and it says  

quote:
Success!
No problems were found with your installation. You should be able to run calendar and calendar_admin successfully!

But I'm still getting a 500 Internal Server Error. Not sure what to try next. I'd really like to get this resolved.


Thanks!
Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle www.newslettersandmore.net

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #10 on: July 19, 2004, 06:46:00 PM »

UPDATE: After some fussing and asking for help from my geek brother, he figured out to comment back out the base path! Don't ask me why, but that fixed it so the calendar now shows up!

BUT, it's still not all joy.

There was an extra box with code in it that we got rid of...but not sure what potential ill effects that might have. AND the Calendar month still does not change on request so we need to figure that out.

FINALLY, we have NOT retained the event data that was there. Is it still possible it's there somewhere? If so how to find it? If not, why not?

Thanks again,
Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle www.newslettersandmore.net

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

[This message has been edited by Sheila Hoffman (edited July 19, 2004).]

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #11 on: July 19, 2004, 09:02:00 PM »

** There was an extra box with code in it that we got rid of... but not sure what potential ill effects that might have. **

I doubt anyone here will be able to tell you with such a vague description. Sorry.

** I downloaded the full 3.2.1 ... , we have NOT retained the event data that was there. Is it still possible it's there somewhere? **

Not unless you kept a backup of the original server files. Otherwise they're g-o-n-e!  

Dan O.

PS. The current version is actually "3.21" not 3.2.1

JFYI

------------------

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #12 on: July 19, 2004, 11:38:00 PM »

Dan:

I had the impression that installing over the old version would retain the data. Oh well...guess it's lost.

Now, is there any way to troubleshoot why the month drop-down doesn't take the user to the month? If I can't get it to work, where would I go to just remove the option?

Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

DanO
Moderator
Full Member
*****

Karma: 13
Offline Offline

Posts: 230

Please don't PM me. Post in the open forum.


WWW
« Reply #13 on: July 20, 2004, 12:56:00 PM »

** I had the impression that installing over the old version would retain the data. **

JFYI. This was the previous reply:

quote:

** IF there's anyway to retain the current calendar entries it would sure be helpful to know **

Use the upgrades.


** is there any way to troubleshoot why the month drop-down doesn't take the user to the month? **

What month drop-down and where? (Tip: a link to the page experiencing the problem would probably be helpful.)

You're sure it has nothing to do with "There was an extra box with code in it that we got rid of..."?

Dan O.

------------------

Logged
Sheila Hoffman
New Member
*

Karma: 0
Offline Offline

Posts: 0

graphic designer


WWW
« Reply #14 on: July 20, 2004, 06:17:00 PM »

Dan:

If you go to www.eastsidearts.org/cgi-bin/debug.pl  what WAS reading Success now shows exactly what WAS being displayed on my calendar until we remarked it out. I'd sure like to get this cleaned up. I've told the client about the problem and they're starting to re-enter events. I don't want to end up having to loose them AGAIN.

I need to figure out why the month go-box doesn't work.
Thanks for taking a look.

Sheila

------------------
Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Logged

Sheila Hoffman
Newsletters & More
Fast, Affordable, Effective
Full-Service Web & Print Design in Seattle
www.newslettersandmore.net

Pages: [1] 2   Go Up
Print
Jump to: