1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

I think my website was hacked. Please help!

Discussion in 'Security' started by duncan107, Aug 12, 2010.

  1. #1
    Hi everybody,

    I went to my blog half an hour ago and it was full of ads I never placed. However, pretty much else was in place? Was that a hack? And if yes, why they didn't touch anything else? How did they do that?

    Also, please let me know if there are any security programs out there that could prevent something like that from happening!

    Thanks a lot!

    Duncan
     
    duncan107, Aug 12, 2010 IP
  2. ZeeshanButt

    ZeeshanButt Well-Known Member

    Messages:
    307
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    110
    #2
    What is your blog url?
     
    ZeeshanButt, Aug 12, 2010 IP
  3. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Thank you ZeeshanButt!

    I removed all the ads by changing the main.tpl file to the original one.

    But I am still scared as hell... :-(
     
    duncan107, Aug 12, 2010 IP
  4. BreezeHost

    BreezeHost Member

    Messages:
    139
    Likes Received:
    1
    Best Answers:
    1
    Trophy Points:
    28
    #4
    You can check ftp logs that might help you to locate IP from which files uploaded in your account.
     
    BreezeHost, Aug 13, 2010 IP
  5. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Yes you were hacked. Simply replacing the template with the unhacked version isn't fixing the problem. You should update your blog software to the latest version, and see if you can work out how they managed to edit files on you hosting account.
     
    phpSiteMinder, Aug 13, 2010 IP
  6. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Thank you guys!

    I already checked my logs without too much luck.

    But I haven't updated my software to the latest version. I should probably do that immediately.

    Sincerely,

    Duncan

    Btw, you wouldn't happen to know how to update a datalife engine template would you?
     
    Last edited: Aug 13, 2010
    duncan107, Aug 13, 2010 IP
  7. myrevshare

    myrevshare Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    you should also check if there's any backdoor left behind. Usually when bad guy hacks a web site, he will drop a web shell between your file so he can come back later.
     
    myrevshare, Aug 14, 2010 IP
  8. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    How do I check that?
     
    duncan107, Aug 14, 2010 IP
  9. phpSiteMinder

    phpSiteMinder Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Well you could check ever single files contents one by one manually to see if they are a back door script, or you could use phpSiteScanner, which scans for backdoor scripts and other code that might be used to compromise your server.
     
    phpSiteMinder, Aug 15, 2010 IP
  10. Asad Ullah

    Asad Ullah Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    can you tell me your blog url i can help you in datalife
     
    Asad Ullah, Aug 28, 2010 IP
  11. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Thank you Asad for your help,

    But I think I already fixed the problem! ;-)
     
    duncan107, Aug 28, 2010 IP
  12. Asad Ullah

    Asad Ullah Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #12
    your web site hass been hack by shell files... thts y the can upload here file again and agin ok change rights of you default templet folder chang in to 644

    then they can't change your main.tpl with shell

    your prb has been slow by that suggation
     
    Asad Ullah, Aug 29, 2010 IP
    duncan107 likes this.
  13. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    So let me see if I get this straight:

    You tell me to go to the following folder in my ftp:

    public_html/templates/x360

    Then right click on x360 (which is my current template) click on "file permissions"
    and then change the number 755 to 644...

    Is that correct?
     
    duncan107, Aug 29, 2010 IP
  14. Asad Ullah

    Asad Ullah Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #14
    ya you corect
     
    Asad Ullah, Aug 30, 2010 IP
  15. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    I don't think this is the right way to do this.

    Every time I do it, the template of the website is ruined and all a I am getting
    is text in white background. :-(
     
    duncan107, Aug 30, 2010 IP
  16. Asad Ullah

    Asad Ullah Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Bro i say you make unwritable your dir bcz i knw a littl bit abut hacking with simpl php filez...
    this file calls shell and they can ad or dell every thinng with is writtble...
    in past i aslo use many of shell thts y i knw that you get that prb...
    they can also download or upload files in your hosting if you folder is writeable

    i think your web have also that prb... i think bcz i also use that methad many times in past

    lolxxxxxxxx

    Asad
     
    Asad Ullah, Aug 31, 2010 IP
  17. King OF vBulletin

    King OF vBulletin Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    You should update your blog software to the latest version , change ur ftp passwords , admin , etc
     
    King OF vBulletin, Aug 31, 2010 IP
  18. Aerty

    Aerty Peon

    Messages:
    1
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #18
    Replace all with your back-up?
     
    Aerty, Aug 31, 2010 IP
  19. duncan107

    duncan107 Peon

    Messages:
    106
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Thank you guys, I ve done most of the above things already.

    Also, Asad the 644 thing would be great if it didn't mess up with the way the website looked to me...
     
    duncan107, Aug 31, 2010 IP
  20. Asad Ullah

    Asad Ullah Peon

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #20
    bro i m not only to give you support

    i can tell you i also hacked many sites whit that prosses in past that was i knw waht that prb in your site
     
    Asad Ullah, Aug 31, 2010 IP