close ad
 
Important WebAssist Announcement
open ad
View Menu

Technical Support Forums

Free, outstanding support from WebAssist and your colleagues

.htaccess file was changed on the server, but not by me

Thread began 3/03/2020 4:38 am by Mags | Last modified 3/03/2020 10:29 am by Mags | 297 views | 2 replies

Mags

.htaccess file was changed on the server, but not by me

Hi Ray, I had a strange issue this morning - I updated one of our sites using PowerCMS a couple of days ago using the Alpha version and upgraded to PHP7. I realised today that I hadn't updated the HTML Editor image upload to point to kcfinder on a separate DataAssist insert & update page. I updated the two pages, changed the config file in the kcfinder directory to point to a different directory, uploaded the three files to the server and also changed the main upload folder directly in the wa_settings table in the database.

However, after that I tried to access the site and got a Page Not Found error - not a PHP error, just Page Not Found. I got this on every page in the site.

After some investigation and raising a support ticket with our dedicated server suppliers, I noticed that the main .htaccess file on the server had been updated this morning - but I hadn't made any changes to it (and I'm the only person with FTP access). So it had basically wiped out all my settings and replaced them with the following:

<IfModule mod_php4.c>
php_flag engine Off
</IfModule>
<IfModule mod_php5.c>
php_flag engine Off
</IfModule>
<IfModule mod_php6.c>
php_flag engine Off
</IfModule>
<IfModule mod_cgi.c>
Options -ExecCGI
</IfModule>

RemoveHandler .cgi .pl .py .pyc .pyo .phtml .php .php3 .php4 .php5 .php6 .pcgi .pcgi3 .pcgi4 .pcgi5 .pchi6 .inc
RemoveType .cgi .pl .py .pyc .pyo .phtml .php .php3 .php4 .php5 .php6 .pcgi .pcgi3 .pcgi4 .pcgi5 .pchi6 .inc
SetHandler None
SetHandler default-handler

# Remove both lines below if you want to render HTML files from the upload folder
AddType text/plain .html
AddType text/plain .htm

I didn't even have a copy of the .htaccess file saved locally, so I couldn't have accidentally uploaded it - and besides, the code above means nothing to me. I was able to restore the file from yesterday's backup, so the site is back up again.

I'm just interested to find out what might have happened - is there a chance that the changes I made in kcfinder might have rewritten the file on the server, or do you think this was an SQL injection attack?

Build websites with a little help from your friends

Your friends over here at WebAssist! These Dreamweaver extensions will assist you in building unlimited, custom websites.

Build websites from already-built web applications

These out-of-the-box solutions provide you proven, tested applications that can be up and running now.  Build a store, a gallery, or a web-based email solution.

Want your website pre-built and hosted?

Close Windowclose

Rate your experience or provide feedback on this page

Account or customer service questions?
Please user our contact form.

Need technical support?
Please visit support to ask a question

Content

rating

Layout

rating

Ease of use

rating

security code refresh image

We do not respond to comments submitted from this page directly, but we do read and analyze any feedback and will use it to help make your experience better in the future.

Close Windowclose

We were unable to retrieve the attached file

Close Windowclose

Attach and remove files

add attachmentAdd attachment
Close Windowclose

Enter the URL you would like to link to in your post

Close Windowclose

This is how you use right click RTF editing

Enable right click RTF editing option allows you to add html markup into your tutorial such as images, bulleted lists, files and more...

-- click to close --

Uploading file...