ScarletPages Hacked

Discussion in 'Directories' started by syted, Sep 1, 2007.

  1. #1
    syted, Sep 1, 2007 IP
    funkymario likes this.
  2. The Pheonix

    The Pheonix Banned

    Messages:
    1,233
    Likes Received:
    96
    Best Answers:
    0
    Trophy Points:
    0
    #2
    The Pheonix, Sep 1, 2007 IP
  3. sachin410

    sachin410 Illustrious Member

    Messages:
    6,422
    Likes Received:
    573
    Best Answers:
    0
    Trophy Points:
    410
    #3
    It is 3.0.6...that's not the latest version.
     
    sachin410, Sep 1, 2007 IP
  4. The Pheonix

    The Pheonix Banned

    Messages:
    1,233
    Likes Received:
    96
    Best Answers:
    0
    Trophy Points:
    0
    #4
    ain't it? Okay. Not up on phpld too much just do the editing for a few customers, sorry about that. Is it a new problem with phpld or is it something that there is a fix for?
     
    The Pheonix, Sep 1, 2007 IP
  5. jminscoe

    jminscoe Peon

    Messages:
    1,223
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #5
    okay upon reading at phplinkdirectory people are finding that it usually another file or script that is hacked first but somehow leads to getting phpld hacked
     
    jminscoe, Sep 1, 2007 IP
  6. shenron

    shenron Notable Member

    Messages:
    4,965
    Likes Received:
    374
    Best Answers:
    0
    Trophy Points:
    295
    #6
    Latest official Phpld release is 3.2
    3.3 to come out soon i guess. :)
     
    shenron, Sep 1, 2007 IP
  7. jminscoe

    jminscoe Peon

    Messages:
    1,223
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Whois Record
    Domain name:
    scarletpages.co.uk

    Registrant:
    Stephen Pratley

    Registrant type:
    UK Individual

    Registrant's address:
    The registrant is a non-trading individual who has opted to have their
    address omitted from the WHOIS service.

    Registrar:
    Schlund + Partner AG [Tag = SCHLUND]
    URL: http://registrar.schlund.info

    Relevant dates:
    Registered on: 14-Jul-2004
    Renewal date: 14-Jul-2008
    Last updated: 13-Jul-2006

    Registration status:
    Registered until renewal date.

    Name servers:
    ns33.1and1.co.uk
    ns34.1and1.co.uk
     
    jminscoe, Sep 1, 2007 IP
  8. The Pheonix

    The Pheonix Banned

    Messages:
    1,233
    Likes Received:
    96
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Can't see that being the case, gonna look into it though and hope it's something that's already been addressed before, or if I find any exploit regardless of my allegiance I'll post it here, one things for sure we got to unite on at least one thing and thats' against hacking.
     
    The Pheonix, Sep 1, 2007 IP
  9. syted

    syted Notable Member

    Messages:
    2,086
    Likes Received:
    319
    Best Answers:
    0
    Trophy Points:
    290
    #9
    I contacted 1&1 and they are working on it.
     
    syted, Sep 1, 2007 IP
  10. jminscoe

    jminscoe Peon

    Messages:
    1,223
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #10
    jminscoe, Sep 1, 2007 IP
  11. jminscoe

    jminscoe Peon

    Messages:
    1,223
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #11
    jminscoe, Sep 1, 2007 IP
  12. The Pheonix

    The Pheonix Banned

    Messages:
    1,233
    Likes Received:
    96
    Best Answers:
    0
    Trophy Points:
    0
    #12
    hmmm, puzzling, the three examples above are all owned by the same person. (name above). I just spoke to 1and1 tech support and they never knew of this but did say they didn't think it was their servers. Have pointed them to this thread so they hopefully can clear things up and give answers.
     
    The Pheonix, Sep 1, 2007 IP
  13. localboy

    localboy Peon

    Messages:
    5
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    hmm, if it is easily broken into, I don't think that I will be interested in using their script for my possible future directory
     
    localboy, Sep 1, 2007 IP
  14. indyguidedotinfo

    indyguidedotinfo Notable Member

    Messages:
    3,254
    Likes Received:
    202
    Best Answers:
    0
    Trophy Points:
    245
    #14
    it might not the be scripts fault. The server might not have all the latest patches .
     
    indyguidedotinfo, Sep 1, 2007 IP
  15. msolution

    msolution Well-Known Member

    Messages:
    1,182
    Likes Received:
    123
    Best Answers:
    0
    Trophy Points:
    175
    #15
    all 3 on the same server.... i think the server has more got to do with it,
    but phpLD people should look into this

    M.
     
    msolution, Sep 1, 2007 IP
  16. indyguidedotinfo

    indyguidedotinfo Notable Member

    Messages:
    3,254
    Likes Received:
    202
    Best Answers:
    0
    Trophy Points:
    245
    #16
    i checked the site on http://www.netcraft.com to see what OS its running but it does not say :(. I bet its probably windows!
     
    indyguidedotinfo, Sep 1, 2007 IP
  17. MrGamma

    MrGamma Peon

    Messages:
    26
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    You would think the hacker would take the chance to promote a website with a few links huh? What a waste...
     
    MrGamma, Sep 1, 2007 IP
  18. Fastian

    Fastian Peon

    Messages:
    2,085
    Likes Received:
    235
    Best Answers:
    0
    Trophy Points:
    0
    #18
    I am sure this is not a phpLD related issue.

    I most cases, such issues turn out to be a server wide attack where index.php file is overwritten by the hacker. The owner's first priority should be to ask host if there was something on their end.

    The DB seems to be intact and you can even see submit page
    http://www.scarletpages.co.uk/submit.php

    In any case, I hope the owner have his backup and will sort it out.
     
    Fastian, Sep 1, 2007 IP
  19. jkrish41

    jkrish41 Banned

    Messages:
    2,416
    Likes Received:
    111
    Best Answers:
    0
    Trophy Points:
    0
    #19
    I am pretty sure there is an exploit where they can use SQL injection on the directory, and they see if password with directory matches their actual cpanel login or FTP access....
     
    jkrish41, Sep 1, 2007 IP
  20. jminscoe

    jminscoe Peon

    Messages:
    1,223
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #20
    well I have the owner http://www.stephenpratley.com/ and have emailed him when you check the header of the submit page it showed the company he worked for
     
    jminscoe, Sep 1, 2007 IP