View Single Post
Old 12-17-2008, 09:28 AM   #136 (permalink)
f.montoya
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 5,718
Thanked 140x in 68 posts
Quote:
Originally Posted by Alan T View Post
Molarmite, does the FTP account used in the league file have full website access, or only access to the export upload directory?

If you are 100% confident that whomever is hacking has the logon/password and not using any site scripts to hack the server, then you probably have an account that has too much access. Restrict the account in the league file to only having ftp rights to the export/import directory and that should also help keep people from hacking your webpage.
Alan T, Molarmite currently has an all access FTP account. However, his most recent infiltration was only to his forum. Being his webhost, I'd like him to follow your advice in getting his machine scanned for any malware/trojan before we go on to the next steps(such as limited FTP accounts for the game only, etc.). His main site has been untouched since the attacks from last month, but that is not to say it is safe.

That said, I continue to see that the hacker is also placing iframes directly into the league reports as well. So I'm afraid that even a restricted FTP account for the game will not stop this cycle.
__________________
Fidel Montoya

Asahi2 Baseball Commissioner(Historical League Since 2004)
www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - Sign up, Connect OOTP and Play!)
Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required)
f.montoya is offline   Reply With Quote