problem accessing admin - eSyndiCat User Forums
eSyndiCat User Forums esyndicat directory software esyndicat support

Go Back   eSyndiCat User Forums > eSyndiCat Directory Software [FREE] > Installation and Updates

Installation and Updates No need to be a programming guru to get started with eSyndiCat Directory Software. Even a newbie can run installation process smoothly with solutions found here.

Reply
 
Thread Tools Display Modes
Old 08-19-2006   #1
tonyhancock
 
Join Date: Oct 2005
Posts: 13
tonyhancock has disabled reputation
Default problem accessing admin

you guys were kind enough to install for me

when i try to login to admin i get

"headers already sent" etc etc

admin login at

http://www.employment40plus.com.au/dir/admin/

can you help please?

cheers
tony
tonyhancock is offline   Reply With Quote
Old 08-19-2006   #2
WTM
Loyal User
 
WTM's Avatar
 
Join Date: Feb 2006
Location: Mockba - New York
Posts: 1,354
WTM is on a distinguished road
Send a message via Skype™ to WTM
Default

Tony,
whats with those 4 iframes that you have above the head?
may be this what couses the problem...
WTM is offline   Reply With Quote
Old 08-21-2006   #3
Vincent Wright
 
Join Date: Sep 2005
Posts: 1,421
Vincent Wright is an unknown quantity at this point
Default

Please open your includes/config.inc.php file and make sure it has NO whitespace after the closing ?> tag.
Vincent Wright is offline   Reply With Quote
Old 08-27-2006   #4
tonyhancock
 
Join Date: Oct 2005
Posts: 13
tonyhancock has disabled reputation
Default step57 hack was the problem

Hi there,

thanks for the suggestions.

All my cpanel administered hosted sites were attacked by the step57 malicious script. More (but not complete) info on step57 can be found at http://ebiz-iq.com/moodle/mod/forum/discuss.php?d=110 or just google step57.

Apparently step57 is a cpanel hack that then allows any writeable file (777, 666) to have iframes inserted and saved. They will then attempt to redirect the user to the step57 site from where other malware can attack the users computer.

To remove step57 from esyndicat I did the following;

1) download a complete backup of all the website files to your local machine.
2) use a program that can search all files - i use bbedit - and search for 'step57'
3) note the file names and paths
4) go back to your server and edit the files removing the iframes
5) the files will have had permissions such as 666 or 777 - change to 644 or 755 (**NOTE** see below)

Apparently there is little that can be done to prevent reinfection until cpanel change there code - HOWEVER ...

**NOTE**
In my instance there were 4 infected files
dir/includes/config.inc.php
esyndicat/includes/config.inc.php
dir/language/English.php
esyndicat/language/English.php

All these files had permissions of 777
I have changed to 755

I think that the 777 permissions were set like this out of the box?
I have not tested esyndicat yet to see if it operates correctly with them set to 755?

Anyway - perhaps the esyndicat dev team could examine the req permissions and advise or patch?

Any files in any scripted solution that have to have 777 or 666 will be vunerable to step57 until cpanel fix their problem.

Cheers
Tony
tonyhancock is offline   Reply With Quote
Old 09-16-2006   #5
Vincent Wright
 
Join Date: Sep 2005
Posts: 1,421
Vincent Wright is an unknown quantity at this point
Default

In the next version we will get rid of as many 777 files as possible.

And hope CPanel team will fix the bug.
Vincent Wright is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 03:46 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Testimonials | Articles | Support | Documentation | Privacy Policy | License | Affiliates | Contact Us | SEO Resources