1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

My directory was hacked

Discussion in 'Directories' started by alang, Dec 7, 2007.

  1. #1
    What happen to my directory was similar to what happen to Aaron Nimock before. Somebody hack into my phpld admin and changed the paypal ID. And somehow he managed to approve all the submission.

    My directory is www.szab.net and using phpld 3.2. I realized that I received submission since November 30th but no payment received. Since that I'm on vacation right now, I unable to to check it until today.

    The hacker paypal email is and the language for his paypal account is french.
     
    alang, Dec 7, 2007 IP
    Brian1970 and nextdir like this.
  2. Brian1970

    Brian1970 Notable Member

    Messages:
    2,886
    Likes Received:
    416
    Best Answers:
    1
    Trophy Points:
    290
    #2
    Are you saying someone cracked your password and changed the payment address?

    Thanks Brian
     
    Brian1970, Dec 7, 2007 IP
  3. Red_Virus

    Red_Virus Well-Known Member

    Messages:
    3,756
    Likes Received:
    249
    Best Answers:
    0
    Trophy Points:
    135
    #3
    So how did the guy cracked your admin password (check the logs) and did u file a complaint with Paypal. I know by this time It will be really difficult to get the money back !

    I know that you will be having two admin panel's.
     
    Red_Virus, Dec 7, 2007 IP
  4. alang

    alang Notable Member

    Messages:
    2,021
    Likes Received:
    220
    Best Answers:
    0
    Trophy Points:
    235
    #4
    I have no idea how he managed to login to change my paypal ID. Whether he somehow know my password or there are some way he can change paypal ID without login to admin panel.

    Could someone please inform me how I can check the logs? I'm not expecting to get my money back though, just want to prevent it to happen again in the future.
     
    alang, Dec 7, 2007 IP
  5. xc06

    xc06 Notable Member

    Messages:
    3,498
    Likes Received:
    332
    Best Answers:
    0
    Trophy Points:
    203
    #5
    this is serious.

    Maybe you can tell this story in phplinkdirectory forum too.
     
    xc06, Dec 7, 2007 IP
  6. hosting.network

    hosting.network Banned

    Messages:
    285
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    lol rfi pwned
     
    hosting.network, Dec 7, 2007 IP
  7. nextdir

    nextdir Peon

    Messages:
    441
    Likes Received:
    37
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Exactly as said xc06, you must mention it at phplinkdirectory so they check whtats wrong with there software.

    I hope installation files were removed and chmode of config.php was not 777
    Fell sorry for you though.

    Best of luck in future.
     
    nextdir, Dec 7, 2007 IP
  8. killaklown

    killaklown Well-Known Member

    Messages:
    2,666
    Likes Received:
    87
    Best Answers:
    0
    Trophy Points:
    165
    #8
    I would put a password protect on the admin folder for now until you find out whats wrong, therefore if he cracked your password, he'll need to do it twice, and youll notice if hes trying because of all the failed attempts.
     
    killaklown, Dec 7, 2007 IP
  9. infogle

    infogle Prominent Member

    Messages:
    2,732
    Likes Received:
    128
    Best Answers:
    1
    Trophy Points:
    300
    #9
    there is one thing you can do... is product the admin directory with the password... and as admin will be having one more password to login so there will be double security in future to protect you and your directory...

    hope it helps.....
     
    infogle, Dec 7, 2007 IP
  10. smub

    smub Notable Member

    Messages:
    3,443
    Likes Received:
    375
    Best Answers:
    0
    Trophy Points:
    230
    #10
    it could be the duo combination of admin panel as you can change paypal email from both i believe ...

    and if ur config file was chmod777 then u invited this trouble on yourself.
     
    smub, Dec 7, 2007 IP
  11. paidhosting

    paidhosting Peon

    Messages:
    4,822
    Likes Received:
    483
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Or even better ip protected like http://www.h-log.com/admin/ i am sure most will see forbidden page there.

    And even better chmod admin folder to 0000 via ftp and when editing just chmod back to 0755 :).

    Cheers
     
    paidhosting, Dec 7, 2007 IP
  12. nextdir

    nextdir Peon

    Messages:
    441
    Likes Received:
    37
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Normal admin page for me, but google ads on top ;)
     
    nextdir, Dec 7, 2007 IP
  13. paidhosting

    paidhosting Peon

    Messages:
    4,822
    Likes Received:
    483
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Damn ur ip matches mine than :D
     
    paidhosting, Dec 7, 2007 IP
  14. mikey1090

    mikey1090 Moderator Staff

    Messages:
    15,869
    Likes Received:
    1,055
    Best Answers:
    0
    Trophy Points:
    445
    Digital Goods:
    2
    #14
    www.zorg-links.com/admin

    people dont even get chance to play with my login form. so easy to implement using cpanel...
     
    mikey1090, Dec 7, 2007 IP
  15. nextdir

    nextdir Peon

    Messages:
    441
    Likes Received:
    37
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Thats very nice.
     
    nextdir, Dec 7, 2007 IP
  16. smub

    smub Notable Member

    Messages:
    3,443
    Likes Received:
    375
    Best Answers:
    0
    Trophy Points:
    230
    #16
    hmm ... i see urs thing too you must be earning good cash because everyone have same ip as yours lol.
     
    smub, Dec 7, 2007 IP
  17. newzone

    newzone Well-Known Member

    Messages:
    2,865
    Likes Received:
    52
    Best Answers:
    0
    Trophy Points:
    135
    Digital Goods:
    1
    #17
    replaced the paypal ID ? first thing in my mind is ...you know his paypal ID ? report the incident to paypal and find the guy, is something serious here... my opinion
     
    newzone, Dec 7, 2007 IP
  18. dynn

    dynn Notable Member

    Messages:
    5,046
    Likes Received:
    238
    Best Answers:
    0
    Trophy Points:
    253
    #18
    why not report to paypal about this fraud since u have the paypal id.
     
    dynn, Dec 7, 2007 IP
  19. fear

    fear Banned

    Messages:
    3,750
    Likes Received:
    221
    Best Answers:
    0
    Trophy Points:
    205
    #19
    My www.paidwebdirectory.com was also hacked and he changed the paypal email, and when i contacted paypal they said we cant do anything as it was a digital delivery.
     
    fear, Dec 7, 2007 IP
  20. Red_Virus

    Red_Virus Well-Known Member

    Messages:
    3,756
    Likes Received:
    249
    Best Answers:
    0
    Trophy Points:
    135
    #20
    Hey Even I see your admin page, that means that the IP filtering method to restrict the admin panel is not working.

    Hi Mikey, that is nice and simple trick. Just placing an .htaacess file in the admin folder, which can also be done from the Cpanel :)

     
    Red_Virus, Dec 8, 2007 IP