1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Drupal hacked?

Discussion in 'Security' started by andre75, Feb 27, 2007.

  1. #1
    Today my two main sites went down. Unfortunately I was out all day and I noticed very late.:confused:
    This morning one of my sites went down and I didn't think much of it, I restored the database. This evening other sites are down too with the same result.

    Basically it was like some of the database tables were emptied out. Even though everything was running, the pages came up almost blank and the menus were gone too.
    I have now updated all my sites to the latest version of Drupal.

    Has anyone seen this before? How can I found out what really happened? Maybe my hosts mysql is messed up?
     
    andre75, Feb 27, 2007 IP
  2. rootbinbash

    rootbinbash Peon

    Messages:
    2,198
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
  3. andre75

    andre75 Peon

    Messages:
    1,203
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #3
    andre75, Feb 27, 2007 IP
  4. crazyryan

    crazyryan Well-Known Member

    Messages:
    3,087
    Likes Received:
    165
    Best Answers:
    0
    Trophy Points:
    175
  5. andre75

    andre75 Peon

    Messages:
    1,203
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #5
    That site is blocked by my company proxy :rolleyes:

    I think the next time I go on vacation I will have to find someone to have an eye on my stuff. Fortunately I just implemented a new backup strategy. Now my database gets backed up every hour and rsynced to a machine at home every 6 hours.
     
    andre75, Feb 27, 2007 IP
  6. AdminZoom

    AdminZoom Peon

    Messages:
    11
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    What version of Drupal were you running?
     
    AdminZoom, Feb 28, 2007 IP
  7. andre75

    andre75 Peon

    Messages:
    1,203
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I upgraded. Why do you ask?
     
    andre75, Feb 28, 2007 IP
  8. nddb

    nddb Peon

    Messages:
    803
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    0
    #8
    i know there was an xml-rpc bug that came with drupal. But it could be sql injection as well. Where someone is just emptying your tables. Or it could just be happening because of some bug in some code somewhere. If you have anything homegrown, i would look there first.
     
    nddb, Mar 2, 2007 IP
  9. andre75

    andre75 Peon

    Messages:
    1,203
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Well, I am not sure what really happened. I checked the DB and everything seemed to be in the tables, but Drupal didn't pull the correct informatin (could have been a corrupt cache table). Anyways, I have not had any problems since I upgraded Drupal. I also removded the xml-rpc and update php files (I don't need update until the next update and I don't use xmlrpc.
    So far I have not had any more trouble.
     
    andre75, Mar 3, 2007 IP