![]() |
|
Something fishy with the htaccess file - Printable Version +- ZenphotoCMS Forum (https://forum.zenphoto.org) +-- Forum: Support (https://forum.zenphoto.org/forum-1.html) +--- Forum: General support (https://forum.zenphoto.org/forum-4.html) +--- Thread: Something fishy with the htaccess file (/thread-9346.html) |
Something fishy with the htaccess file - Moritz83 - 2011-12-05 Hey guys just wanna to share something fishy. I set up my page 2 months ago and stopped working on it cause of too much work at the office. At this point it was running smoothly without any problem. Today I visit my page again to continue my work and I was not able to open it. It was only giving me an 500 error. I thought it might be the htaccess file so I deleted it, rerun the setup process and it's working again. Here is my question: I've seen that the htaccess has been edited today (when I tried to visit the page). Is this correct? I set the permissions to 0664, otherwise it won't work. Is this fine or should it be something else? And why has it been edited? Now I am running Zenphoto 1.4.1.6 and the masonary theme 1.4.1 so I am more or less up2date. Something fishy with the htaccess file - fretzl - 2011-12-05 Probably your site has been hacked too. There are a lot of posts about this on the forum. Zenphoto 1.4.1.6 is the safe/patched version. Something fishy with the htaccess file - Moritz83 - 2011-12-05 So with 1.4.1.6, a new user / password and a fresh .htaccess I am safe or is it neccessary to follow the steps in "Security Alert Part 2"? I could setup a fresh installation as well if needed, just need to know Something fishy with the htaccess file - fretzl - 2011-12-05 Better be safe than sorry then. I recommend you start with a fresh install. Backup your database. Good luck Something fishy with the htaccess file - Moritz83 - 2011-12-05 so I am doing the following:
I am using the zpmasonry theme at the moment. Can I backup (I made a few changes to the templates I don't want to lose) and restore it too? Thank you very much for your help! Something fishy with the htaccess file - acrylian - 2011-12-05 You should always make your own custom copy if you modified a theme (zpmasonry is not official so it has nothing to do with the install/update directly). if you use the Zenphoto tool for backuping you should also not deletle the backup folder. If you backup your database for re-importing you probably should take a look at its contents in case you were indeed hacked. Otherwise you would restore the hacked contents as well. As far as we know the at least specific recent hacks did not affect the database. Something fishy with the htaccess file - Moritz83 - 2011-12-05 In this case I will install 1.4.1.6 and start over from 0, think it's not taking much longer than analysing the database and stuff. By the way, I am not using the "Zenphoto Tool" for a backup, always using my FTP client so I can decide what to backup and exclude everything else. Why is it better to make a custom copy than changing the original theme directly? Thank you for your help! Something fishy with the htaccess file - fretzl - 2011-12-05 Quote:I am not using the "Zenphoto Tool" for a backup Check all your zpMasonry files to be absolutely sure ther is no malicious code inserted somewhere. Quote:Why is it better to make a custom copy than changing the original theme directly? Something fishy with the htaccess file - Moritz83 - 2011-12-06 I've done everything and my site is back again. Took me about 3 hours to get back on track but now I should be safe. Thank you for your help |