CMS Builder Hacked - Help!

2 posts by 2 authors in: Forums > CMS Builder
Last Post: June 3, 2011   (RSS)

Re: [degreesnorth] CMS Builder Hacked - Help!

By Dave - June 3, 2011

Hi degreesnorth,

CMS Builder doesn't have any known security vulnerabilities and has never been hacked. What has likely happened is either another script on the site or the host itself has been hacked and then the hacker (or an automated hacking script) modified any files it could that were writable by PHP.

Common entry points are older Wordpress installs, older open source software, email contact forms, etc. Hackers write automated scripts to scan for known vulnerable versions. Also if another user on the host was compromised they may have used that as an entry point.

You can safely reduce access on any CMSB files with CHMOD and the program will alert you if it can't access those files. In general, though, if CMSB can access a file (even with CHMOD 644) it means other PHP scripts can access the same file, so it doesn't usually help a whole lot unless everything is secure.

Let me know how we can best assist. Feel free to email direct if needed to dave@interactivetools.com.

Hope that helps!
Dave Edis - Senior Developer
interactivetools.com