View Single Post
  #188  
Old 10-30-2008, 10:23 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
1. FTP
2. WHM (have my own server)
3. X-cart Logins

When you say WHM - I am not sure if you are including your database passwords. If not - it is advisable to change those as well. Your config.php file has your db passwords in it and if someone had access to your site - they could have picked them up.

There have been no database exploits reported in this thread, but best to be safe.

It is really not advisable to go through your files one by one. Not only is it time consuming - it is inefficient. You could miss something. Talk to you host about the scripts in post 64 + the added advise in post 143. Also, send the last bit of advise (after "Dear recommended hosting providers") from Ene in post 139 to your hosting provider and see if they can implement that.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote