Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
site hacked by deleting database.php
my site got hacked this evening by way of deleting the database.php file. sounds a lot like the forum hacked by deleting settings.php thread. can anyone think of where i would have gotten that exploit??
0
This discussion has been closed.
Comments
i have quite a few extensions running:
Announcement 1.2
Attachments 2.1
Better BB Code 1.0
Crude RSS 1.0.4
Discussion View Count 1.2.1
Flickrizer 0.3
Google Analytics 1.2
Hidden Text 1.4
HTML Formatter 2.3
Inline Images 1.3
Latest Posts Integ. 1.1
Mark All Read 1.0.1
Members Page 1.2.1
New Applicants 1.3
Next Unread 1.0
Nuggets 1.1.4
Poll 1.3
Preview Post 2.5.1
Quotations 1.6 (?)
Vanillazilla 1.0.1
Who's Online 1.2
Yellow Fade 0.1
so there's that. now it appears my settings.php isn't writable (644) by vanilla. the "do you want addons" message is still lingering. what are safe permissions for database.php and settings.php? 755?
edit - (it was code playing up) - found the solution to my problem.
if you're certain that you were actually hacked because of a vulnerability in vanilla, that's one thing. but otherwise, please don't alarm the community.
i mean you guys can say it wasn't a 'hack', and that's fine. but all day my forum was fine and then after dinner it went kaputz. the only thing database.php related is that someone might have tried to upload a file or something with Attachments (?).