First of all please excuse myself, I am still quite a new to OJS and web site development altogther.
I am helping an employer move an existing academic journal onto an OJS system but we are running into troubles. Any help, advise or direction would be greatly appreciated.
Firstly we had no problems setting up the website and following the very helpful instructions, we are now coming to understand how OJS works and am so far very pleased with what it has to offer.
After about a week of testing, publishing articles and reviewing etc we found our site infected with a Trojan Downloader Laugma.AB virus. It was downloading other viruses to client machines.
I am unsure how this happened, but I suspect it had something to do with the file permission settings that we had to change on installation.
I did this by using the file properties via my ftp client as opposed to the unix commandl; I havent taken the time to learn to do this yet.
My question is: is this the reason we got hacked, and is there some other way we can avoid this?. If not any ideas would be much appreciated.
Thanks alot
James
+++++++++++
We're using
OJS2.1.1
Linux web server.
Php 4.4.6
MySQL 4.1.20
+++++++++++
