Help my site keep being hacked :(

Discussion in 'Programming' started by vaf0r, Sep 7, 2006.

  1. #1
    Hello i hosting a myspace resource site on godaddy and it keeps being hacked b4 the guy just delited all my files but now i have seen he have also removed my google pub id and inserted his own!!

    I looking for some one thath can help me look for securety problems on this site url i can give if u pm. Is it my site or is it godaddys servers that make it posible to hack in and change my files etc?
     
    vaf0r, Sep 7, 2006 IP
  2. tbarr60

    tbarr60 Notable Member

    Messages:
    3,455
    Likes Received:
    125
    Best Answers:
    0
    Trophy Points:
    210
    #2
    Do you have a simple password for accessing your site? Try changing the password.

    Also look at the log files to see how the hacker got it in. There may be terms like SELECT or activities on an admin.php page if you have one.

    Are you using any freeware like phpNuke, phpBB, or ???
     
    tbarr60, Sep 7, 2006 IP
  3. vaf0r

    vaf0r Peon

    Messages:
    371
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #3
    i have tyed to change my pass 2 times using totaly random password forexmapel : uD7-pP48 the godaddy dont have logs i have asked 2 times cuz i have to times payed them 150$ to restore my files the strange thing is that i have 2 other sites on the same account and they also geting delited i dont know if u use any free things its a turnkey myspace recource script that i know many sites use..
     
    vaf0r, Sep 7, 2006 IP
  4. clancey

    clancey Peon

    Messages:
    1,099
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    0
    #4
    If you are using strong passwords, then the problem is with the scripts that you are using. There is a terrible misconception that just because something is "open source" or "sold" that it has been properly tested and is secure. This is simply not true. I have seen many scripts which contain significant vulnerabilities.

    At a cost of $150 every time you need to restore your files from back up, you need to spend some time and or money making sure your scripts are secure. It is more than worth it.

    I would also be going to the website where you obtained your turnkey script and see whether other people are being hacked and what solutions are available to resolve the issue.
     
    clancey, Sep 7, 2006 IP
  5. tyggemannen

    tyggemannen Guest

    Messages:
    842
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #5
    And of course report the guy to adsense so he loose his account and money.
     
    tyggemannen, Sep 7, 2006 IP
  6. ccoonen

    ccoonen Well-Known Member

    Messages:
    1,606
    Likes Received:
    71
    Best Answers:
    0
    Trophy Points:
    160
    #6
    Whats the url - we'll check it out for security
     
    ccoonen, Sep 7, 2006 IP
  7. vaf0r

    vaf0r Peon

    Messages:
    371
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #7
    u have a pm :)
     
    vaf0r, Sep 10, 2006 IP
  8. Psychotomus

    Psychotomus Guest

    Messages:
    427
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #8
    send me url too.
     
    Psychotomus, Sep 11, 2006 IP
  9. Jdog

    Jdog Peon

    Messages:
    267
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #9
    A lot of myspace sites have an upload a pic script that is an open door to hackers. I disabled the one on my sites.
     
    Jdog, Sep 11, 2006 IP
  10. spencer69

    spencer69 Member

    Messages:
    38
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    43
    #10
    can you send me url too?

    if you changed it to a strong password, and was hacked fast, then it must be an inside job don't you think? someone from your organization or team, or you have a spyware on your computer that logs your actions... :)
     
    spencer69, Sep 11, 2006 IP
  11. america2

    america2 Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I had this issue with Lunarpages. Godaddy's tech team SHOULD be inspecting all the logs to let you know how the guy is breaking in. If godaddy is doing nothing to help you stop the hacking, you need to change hosts. Consider Rackspace - they're expensive but they know their shit. This was the advice I got from the FBI when my site was under attack - not to go to Rackspace but to change hosts. The really big shared hosting companies just don't give a dma if you get hacked but a good hosting company will know in a minute how he's breaking in from the logs (unless he's a master hacker which I doubt.)
     
    america2, Sep 15, 2006 IP