Kein Zugriff mehr auf Kontrollzentrum

Phoca Guestbook - creating guestbooks in Joomla! CMS
fneurieser
Phoca Member
Phoca Member
Posts: 41
Joined: 03 Feb 2011, 13:43
Location: Koeflach, Austria
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by fneurieser »

Hi all,

world4you has reactivated my guestbook. but when trying to access the post panel in the control panel in backend I get the following message:

Image

But in the frontend all postings are visible.

and when trying to access the panel guestbook in the control panel in backend the following message is shown:

Image
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 48689
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Jan »

Hi, maybe your items in frontend are displayed by cache, or this errors are displayed by chache - The joomla system says there are no phoca guestbook tables in your database, so the only one chance how to find out this, go to your phpMyadmin and check if the table are there. :idea:

Jan
If you find Phoca extensions useful, please support the project
Andi
Phoca Newbie
Phoca Newbie
Posts: 7
Joined: 31 Mar 2012, 23:11

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Andi »

my hoster is world4you too and they have reactivate my guestbook too. My site has been hacked over the phoca guestbook. Now everything is working fine except the spam on the guestbook. More than 200 spam entries in 24 hours. i have tried several captchas but nothing works really :!:
I think i have to hide the guestbook :(
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 48689
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Jan »

Hi, see:
https://www.phoca.cz/documents/3-phoca-g ... -from-spam

If you have been hacked through the phoca guestbook, please describe it, here, or in PM or into my email, I will be first who will fix the problem if there will be some (but until now - 5 years of phoca guestbook development, nobody described the way how it was done and I really don't understand. Everbody knows that the problem is in phoca guestbook but nobody knows which is the problem - this is really confusing for me :-( )

Anyway:

Trying to prevent from spam:
https://www.phoca.cz/documents/3-phoca-g ... -from-spam

Phoca Guestbook and spam:
https://www.phoca.cz/documents/3-phoca-g ... erver-spam
Jan
If you find Phoca extensions useful, please support the project
grandm
Phoca Newbie
Phoca Newbie
Posts: 1
Joined: 31 Oct 2012, 16:05

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by grandm »

Hi
i don´t know exactly how it was hacked but i noticed that my index.php has changed during the hack

it contanis only the following text:

Code: Select all

<? eval(base64_decode('-code-removed-'));?>
my homepage was forwarded to an ad.fly homepage after a few seconds, no matter on which position i was on the page in the frontend

i hope it helps you with your work
regards
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 48689
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Jan »

Hi, your page was not hacked through Phoca Guestbook. Phoca Guestbook does not have any part which can write something on the server. If somebody changed your index.php - he/she did it probably per FTP or per some script which was allowed to change files on your server. This is not possible per Phoca Guestbook as there is no such feature.

Jan
If you find Phoca extensions useful, please support the project
Andi
Phoca Newbie
Phoca Newbie
Posts: 7
Joined: 31 Mar 2012, 23:11

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Andi »

Hi Jan

I have checked my stats and i have found some interesting things they might help you against spam

http://myurl.at/cms/index.php/gaestebuc ... åøèôðîâàíà

http://www.google.com/recaptcha/api/image

http://www.google.com/recaptcha/api/reload

now i use the TTF captcha and i have no Spam! :)
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 48689
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Jan »

Hi, I get 404 on the first site and some messages on both below - which I don't understand :-(

Jan
If you find Phoca extensions useful, please support the project
world4you
Phoca Newbie
Phoca Newbie
Posts: 2
Joined: 01 Dec 2012, 13:40

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by world4you »

Hi, there is a DoS condition possible with a lot of spam entries in the guestbook which affects both the webserver cpu wise and the used mysql-server. The result is an overloaded webserver, 1Gbit/s bandwitdh usage from the mysql-server to the webserver etc. We tried to get in contact with phoca-developers via mail but got no response so far.

@Jan or any other developer can contact us via PM now - we can give you more technical details
We'd be happy to see that getting fixed.

-World4you
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 48689
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Kein Zugriff mehr auf Kontrollzentrum

Post by Jan »

Hi, contacts sent in PM.
If you find Phoca extensions useful, please support the project
Post Reply