Niche-Listings.com got hacked!

Discussion in 'Directories' started by vnviews, Jan 16, 2007.

  1. #1
    Today I opened the niche-listings.com and saw this message:
     Hacked for Security
    Code (markup):
    Seems that got hacked.
    Can anyone inform to owner?
     
    vnviews, Jan 16, 2007 IP
    romow likes this.
  2. exponent

    exponent Peon

    Messages:
    1,243
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Do a whois on the domain and that should give you the email address you need.
     
    exponent, Jan 16, 2007 IP
  3. onlinedude

    onlinedude Peon

    Messages:
    1,193
    Likes Received:
    322
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Site looks fine to me...
     
    onlinedude, Jan 16, 2007 IP
  4. romow

    romow Peon

    Messages:
    2,166
    Likes Received:
    135
    Best Answers:
    0
    Trophy Points:
    0
    #4
    It seems hacked.
    Check the bottom of the site. The hacker put up his image on it.
     
    romow, Jan 16, 2007 IP
  5. onlinedude

    onlinedude Peon

    Messages:
    1,193
    Likes Received:
    322
    Best Answers:
    0
    Trophy Points:
    0
    #5
    onlinedude, Jan 16, 2007 IP
  6. xc06

    xc06 Notable Member

    Messages:
    3,498
    Likes Received:
    332
    Best Answers:
    0
    Trophy Points:
    203
    #6
    what the purpose of the hacker? just for fun or money?
     
    xc06, Jan 16, 2007 IP
  7. montux

    montux Well-Known Member

    Messages:
    608
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    145
    #7
    I Just talked with previous owner of this site about it. I think he forgot to change CHMOD permission to 755 From 777 that required.
     
    montux, Jan 16, 2007 IP
  8. ccoonen

    ccoonen Well-Known Member

    Messages:
    1,606
    Likes Received:
    71
    Best Answers:
    0
    Trophy Points:
    160
    #8
    Yup, ESyndicat 1.2 has a huge bug, can be fixed by making the /admin/ protected with the .htaccess :)
     
    ccoonen, Jan 16, 2007 IP
  9. an0n

    an0n Prominent Member

    Messages:
    5,688
    Likes Received:
    915
    Best Answers:
    0
    Trophy Points:
    360
    #9
    Well, regardless of the script, I really do not like to see peoples sites get wrecked.

    If you want to pswd protect your admin folder use the link below that will create the necessary info for you to be placed in your htaccess and folders:
    http://www.tools.dynamicdrive.com/password/
     
    an0n, Jan 16, 2007 IP
  10. exponent

    exponent Peon

    Messages:
    1,243
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I used to do it for fun but mainly for educational purposes. I never vandalized anything but I would occasionally hide "X-pwned" in the page source when possible. Thats how the whole "exponent" thing came about. I mainly tested friends websites to make sure everything was secured but I tried my university once. I pointed out the flaw to the university and they promptly fixed it.

    Afterwards, I would usually send an email that I found a security void. OS Commerce is particularly easy.

    As for the "X-pwned", the letter "X" comes from the fact that I use a Macbook when hacking. It runs OS-X. (and I just like the letter). The "pwned" is from playing too many hours of Quake 3. I used "X" as my alias, and the combination of the two was just a fun way to see how long it took someone to fix or update a website.
     
    exponent, Jan 16, 2007 IP
  11. freeprotect

    freeprotect Peon

    Messages:
    56
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    eSyndiCat 1.x has huge bug discovered by my friend hack2prison
    Show this: freeprotect.net?forum=12&thread=41
     
    freeprotect, May 30, 2007 IP