Red Devils Crew Hack my sites!

Discussion in 'General Chat' started by kojakfilth, Sep 9, 2008.

  1. #1
    I've got 200 sites in my windows server and now all of them hacked by these stupid bitches group. No files were deleted but it is pain in the ass to update all of the index.html files one by one.

    I know someone here face this kind of problem right now.

    [​IMG]

    Its not really hack i guess its website defacement.
     
    kojakfilth, Sep 9, 2008 IP
  2. 4hire

    4hire Peon

    Messages:
    55
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I was wondering how do they get access to your server ?

    Pardon my "newbie" question :)
     
    4hire, Sep 9, 2008 IP
  3. hagmund

    hagmund Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Probably security holes in a script like Joomla or something..
     
    hagmund, Sep 9, 2008 IP
  4. kojakfilth

    kojakfilth Notable Member

    Messages:
    3,000
    Likes Received:
    213
    Best Answers:
    0
    Trophy Points:
    210
    #4
    Maybe.. But my static html sites are being deface also. They replace all the index.html with their own index file..
     
    kojakfilth, Sep 9, 2008 IP
  5. javaongsan

    javaongsan Well-Known Member

    Messages:
    1,054
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    128
    #5
    get a unix host.
     
    javaongsan, Sep 10, 2008 IP
  6. hagmund

    hagmund Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Are you on a shared server or your own?
     
    hagmund, Sep 10, 2008 IP
  7. kojakfilth

    kojakfilth Notable Member

    Messages:
    3,000
    Likes Received:
    213
    Best Answers:
    0
    Trophy Points:
    210
    #7
    We have our own dedicated server... Is there any tips to secure our sites? Coz i believe they can do it again if they want.
     
    kojakfilth, Sep 10, 2008 IP
  8. Divisive Cottonwood

    Divisive Cottonwood Peon

    Messages:
    1,674
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    0
    #8
    They would have gotten in via one website and then gone through the lot - they would have entered via a dynamic site, no doubt a security hole in one of your CMS.

    Update all your scripts - that includes core files and all modules and addons.

    The Red Devils Crew have been going for years and are based in Saudi Arabia

    Also as well run a anti-virus scan on your server because they would have likely left some sort of script on there.
     
    Divisive Cottonwood, Sep 10, 2008 IP
  9. glowleaf

    glowleaf Peon

    Messages:
    59
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    That sucks. You need to upgrade all scripts basically.
     
    glowleaf, Sep 10, 2008 IP
  10. agentonline

    agentonline Banned

    Messages:
    115
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    you can htaccess them and password protect the directory in your cpanel if you dedicated server come with cpanel. :)
     
    agentonline, Sep 10, 2008 IP
  11. tuxicy

    tuxicy Member

    Messages:
    79
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #11
    Ban turkish IP's
     
    tuxicy, Sep 10, 2008 IP
  12. surfaddict

    surfaddict Active Member

    Messages:
    1,781
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    90
    #12
    I already been hacked by Syrian Spider, gosh...little bit tired with all the hacker :(
     
    surfaddict, Sep 10, 2008 IP
  13. tradeya

    tradeya Notable Member

    Messages:
    5,729
    Likes Received:
    275
    Best Answers:
    0
    Trophy Points:
    230
    #13
    sorry to hear that. I also dont want this thing to happen to my site as well. hope you can get away from this problem soon.
     
    tradeya, Sep 11, 2008 IP
  14. levampire

    levampire Active Member

    Messages:
    2,463
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    90
    #14
    I guess it is just defacing not hacking .. if they hacked you they would have deleted/Changed all of your files.

    bothways, they may have left a backdoor opened or so .. so take care ;)
     
    levampire, Sep 11, 2008 IP
  15. cpuhlp

    cpuhlp Guest

    Messages:
    112
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Everyone else is saying it and so will I.. You must keep your security updated. The next step is keeping scripts on user accounts upgraded and keep poorly coded scripts off the server. I see this happen on a daily basis at work. Hopefully you keep regular local back up's. :) PM me if you have any security questions.
     
    cpuhlp, Sep 11, 2008 IP
  16. AdamCox9

    AdamCox9 Peon

    Messages:
    37
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #16
    My Joomla! site got taken over by the Red Devils Crew!
     
    AdamCox9, Sep 30, 2008 IP