![]() |
|
|
#1
|
||||
|
||||
|
Topsites hacked with c99shell
Some turkish hackers were targeting my Aardvark topsites & managed to install c99shell on to the account that hosts the topsites script so i want to know what steps i should take to make sure the hacker has left no backdoor to get back in again & want to know what information he could have got.
The account he hacked has a main site, topsites, poll, guestbook & forum but is also on the same server with some of my other sites. What i did was check files dates for recently changed or upload files on the account that was hacked(there was none) I deleted the topsites script & upgraded to the latest version. What other steps would i need to take or should take to make things safe?
__________________
Myspace scripts | Webmaster Scripts and Content! A fool and water will go the way they are diverted. |
|
#2
|
||||
|
||||
|
Probably your permissions are set 777. Make them non-writable. And also, set safe mode on.
|
|
#3
|
||||
|
||||
|
about a year ago i had repeatedly same problem of hacker intrusion - now all solved.
if you give URL and a list of scripts you use online as well as OS - then may be I can help more precisely. however be warned that securing your site requires understanding your site with all scripts - I have spent some 300 hrs total to do just that - then I secured and solved all the problems ... successfully so far until these days. In my case it was a faulty script of a commercial forum software - a bug that was known to the coders but unresolved by them until now - hence almost all those forums get/got hacked until now to upload files for phishing sites. If I look at the frequent hacker attempts on my site and look at what kind of software they search for - that gives a pretty complete picture of the potential scripts they use to enter a site - I safely assume that hackers only search for scripts known to them to have a security hole to penetrate a site. |
|
#4
|
|||
|
|||
|
had a problem like that myself before...absolutely annoying
|
|
#5
|
||||
|
||||
|
I will recommend a fresh install of your hosting account as the hacker could have written malicious code in some other script also. So he can regain access to your website if he wants to.. Usually this code accepts remote file's. So you may need to check those too. Incase you dont want to remove all the script you may need to have a security audit for your website. You may like to check this.
http://forums.digitalpoint.com/showthread.php?t=278457 |
|
#6
|
||||
|
||||
|
Quote:
|
|
#7
|
|||
|
|||
|
c99shell. how lovely. I remember back in the day (last summer) when i used c99shell to access peoples sites and information and also get web space that wasn't mine LOL.
|
|
#8
|
|||
|
|||
|
Hi,
The problem can be either because they got a way to upload files on your webserver (.php files with execute priv) or a bad include (remote file inclusion vulnerability). I would recommend that you do a check with aports to monitor also executables files opening port for shell other than malicious scripts being hijacked (check the forms' action field or anomalous javascript).
__________________
Secure your website - Blog |
|
#9
|
||||
|
||||
|
Some software scripts require permission 777 to run. If that is the case, how do we protect it?
|
|
#10
|
||||
|
||||
|
If you trust your script then you dont have to set perms 777.But be sure you set safe mode on.
__________________
Make Money Blogging You can easily add an aditional income stream of $200 per day.Don't you believe ? Check out proof here http://forums.digitalpoint.com/showthread.php?t=1164345 |
|
#11
|
||||
|
||||
|
Sorry. I think you got it wrong. What I am saying that the script requires to run with perms 777. Without 777, it will give error. For this situation, what can we do to protect that folder from being exploited?
|
|
#12
|
||||
|
||||
|
sorry i wrote it wrong . I was trying to say
If you trust your script then you dont have to set perms not 777.But be sure you set safe mode on.
__________________
Make Money Blogging You can easily add an aditional income stream of $200 per day.Don't you believe ? Check out proof here http://forums.digitalpoint.com/showthread.php?t=1164345 |
|
#13
|
|||
|
|||
|
Quote:
PHP is good for reaching over the wall of an .htaccess for storing, or reading data. Zap ![]() P.S. My GPL/Freeware script ZB Block MAY help avoid injection of c99shell into your website. Get it at www DOT spambotsecurity DOT com SLASH zbblock DOT php Last edited by zaphodb777; May 18th 2009 at 1:10 pm. Reason: Added post-script about ZB Block |
|
#14
|
|||
|
|||
|
aswell as using .htaccess
make sure your admin directory is protected with .htpasswd also make sure you scan your files with clamav or other av |
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Best Arcade Topsites? | Jelf | General Marketing | 4 | Jan 8th 2007 10:31 am |
| Proxy Topsites? | HideIp | Scripts | 4 | Dec 7th 2006 1:32 pm |
| Submit to my topsites | cb711 | Link Exchange | 0 | Nov 30th 2006 8:13 pm |
| TopSites looking for members | siteseer | Services | 0 | Oct 15th 2006 4:45 pm |
| PS3 Topsites | munt | Link Exchange | 0 | Apr 3rd 2006 5:22 am |