My Directories got hacked :(

Discussion in 'Directories' started by fear, Aug 9, 2007.

  1. #1
    Hi everyone,
    Today when I was approving some links and adding some links of Chris, I noticed that there were many transactions in the admin area, all links were approved, but I never had the money, and when I checked the payment section my paypal email was changed :mad:. I had round about $80 sales in this week (as I saw the links) but $0 in my account. So if anyone submitted bought links in my directories just pm me so that he/she can claim a case against that email. My directories are below.
    Bling Directory
    WebDirectory.nu
    LinkWide
    Bidding Directory
    eLinksDir
    I just dont know how he or she got all the passes and was controling on my directories :(.
    Thanks for your time reading the thread.
     
    fear, Aug 9, 2007 IP
  2. malcolm1

    malcolm1 Prominent Member

    Messages:
    7,148
    Likes Received:
    758
    Best Answers:
    0
    Trophy Points:
    310
    #2
    Was this due to the script your using?
    or did you make the admin code really easy?

    Regardless i hope you had backups for your sites..:eek:

    Thx
    malcolm
     
    malcolm1, Aug 9, 2007 IP
  3. overdrive

    overdrive Active Member

    Messages:
    969
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    80
    #3
    Man, I hope you have some recent backups. This is the problem with running things that make money, everyone always wants it!
     
    overdrive, Aug 9, 2007 IP
  4. msolution

    msolution Well-Known Member

    Messages:
    1,182
    Likes Received:
    123
    Best Answers:
    0
    Trophy Points:
    175
    #4
    Hacking is one thing,
    but this is hands down cheating,
    you should report this to Paypal immediately,
    so they can put a hold on that account
    atleast you can get the money!

    M.
     
    msolution, Aug 9, 2007 IP
  5. templates

    templates Notable Member

    Messages:
    4,772
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    205
    #5
    Yea..have you gave anyone access to your admin?maybe installing MOD or something?I ask because there are only a few ppl i trust with this info on my site
     
    templates, Aug 9, 2007 IP
  6. deluxdon

    deluxdon Catch Me If You Can...!!!™ Staff

    Messages:
    25,481
    Likes Received:
    1,943
    Best Answers:
    32
    Trophy Points:
    480
    #6
    Do one thing that check your recent paid links (as you told $80 sales) and if submissions are from any DP members then contact him and ask that where they paid (to which paypal) after submission. May be you'll get some useful info from there IMO.
     
    deluxdon, Aug 9, 2007 IP
  7. tmeyer45458

    tmeyer45458 Peon

    Messages:
    355
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #7
    do a whois of the sites approved w/o payment...if you have any that match then chances are you've found your man...or woman.

    Goodluck w/sorting this out
     
    tmeyer45458, Aug 9, 2007 IP
  8. fear

    fear Banned

    Messages:
    3,750
    Likes Received:
    221
    Best Answers:
    0
    Trophy Points:
    205
    #8
    Site was running on phpldv3.2, I had backups. And yeah I had given access for someone to install mods for me but I trust him.
    And i've got the hackers paypal add also as it was in the directory when i was checking. I've contacted paypal also
     
    fear, Aug 9, 2007 IP
  9. The Pheonix

    The Pheonix Banned

    Messages:
    1,233
    Likes Received:
    96
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I really feel for you mate, this kind of thing is bad. Could it have been the actual mod you isntalled that compromised your script? I don't want you to post what it was here, just have a look at all possibilities.

    I know you said you trust the installer of the mod, (I don't doubt you) but in future make sure you have accurate name and address of them in future as we're all pretty much anonymous on this internet thing.

    Good luck with solving your problems, hope you can.
     
    The Pheonix, Aug 10, 2007 IP
  10. Mr_Kumar

    Mr_Kumar Notable Member

    Messages:
    2,561
    Likes Received:
    374
    Best Answers:
    1
    Trophy Points:
    265
    Articles:
    4
    #10
    Now I think you have the passwords working and full dirs in your control. So you should change all passwords first. And If possible switch to more secure host.

    What?? paypal shows no transaction.
     
    Mr_Kumar, Aug 10, 2007 IP
  11. msolution

    msolution Well-Known Member

    Messages:
    1,182
    Likes Received:
    123
    Best Answers:
    0
    Trophy Points:
    175
    #11
    I didnt get you?

    any transaction which may have happened will show
    the product name and ID, and ...(should show) referrer in
    their logs,.... which would stand proof that payments were made
    for the Fear's site! and has been wrongfuly hijacked and
    put into someone elses account.

    M.
     
    msolution, Aug 10, 2007 IP
  12. fear

    fear Banned

    Messages:
    3,750
    Likes Received:
    221
    Best Answers:
    0
    Trophy Points:
    205
    #12
    Yeah i've changed the pass. Contacted paypal also
     
    fear, Aug 10, 2007 IP
  13. Mr_Kumar

    Mr_Kumar Notable Member

    Messages:
    2,561
    Likes Received:
    374
    Best Answers:
    1
    Trophy Points:
    265
    Articles:
    4
    #13
    I don't think writing to paypal will help. Is this is the case then anyone can write paypal for his enemy's directory after doing just one submissions to directory and seeing what paypal records?

    i hope you get it what I am saying. Just asking query.
     
    Mr_Kumar, Aug 10, 2007 IP
  14. mrcrowley

    mrcrowley Peon

    Messages:
    1,034
    Likes Received:
    54
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Sorry to hear about your situation Fear. Good thing you had backups.
    Best of luck getting it sorted out :)
     
    mrcrowley, Aug 10, 2007 IP