1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Have you ever been hacked?

Discussion in 'Site & Server Administration' started by Nintendo, Apr 21, 2006.

?

Have you ever been hacked?

  1. Yes, on a dedicated server.

    12 vote(s)
    21.8%
  2. Yes, on a shared server.

    21 vote(s)
    38.2%
  3. Yes, on my own computer.

    5 vote(s)
    9.1%
  4. Got phished, tricked in to giving out my username or password.

    4 vote(s)
    7.3%
  5. Yes, got the mySQL password.

    6 vote(s)
    10.9%
  6. Yes, got some other password, like Control Panel, admin area...

    8 vote(s)
    14.5%
  7. Yes, some other way.

    6 vote(s)
    10.9%
  8. Nope... not yet.

    18 vote(s)
    32.7%
Multiple votes are allowed.
  1. #1
    I think many people never think they can get hacked until they actually get hacked!!

    Let's find out how common getting hacked actually is.

    I've been hacked myself a few times. Once my server was used to do a DOS attack on a government site. *gulp* Another time some one got one of my passwords, and quite a few times one of my vBulletin sites have been hacked, mostly from some one getting a Super Mods password some how.

    Heck, back in 1997 on Geocities, I got tricked in to giving out my username and password and with in a day, the site was deleted.
     
    Nintendo, Apr 21, 2006 IP
  2. Crazy_Rob

    Crazy_Rob I seen't it!

    Messages:
    13,157
    Likes Received:
    1,366
    Best Answers:
    0
    Trophy Points:
    360
    #2
    Crazy_Rob, Apr 21, 2006 IP
  3. carowan

    carowan Peon

    Messages:
    473
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #3
    scary. its one thing that i always worry about.....
     
    carowan, Apr 21, 2006 IP
  4. disgust

    disgust Guest

    Messages:
    2,417
    Likes Received:
    133
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I've had some minor compromises, but never anything at the root level, luckily.

    which is a really good thing, as I'm super lazy with backups ;-)
     
    disgust, Apr 21, 2006 IP
  5. forkqueue

    forkqueue Guest

    Messages:
    401
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #5
    My days job involves doing Linux consultancy, part of which means having to find out how attackers got in and re-building newer, more secure servers for the customers.

    Over the past six months, the number of hacked machines I've come across has risen a lot. I'd say in 50% of cases the attackers got in through SSH brute force attacks, where an account had a poor (dictionary word or same as username) password.

    The rest are mainly cracked via the software installed on the machines (awstats, phpbb being the favourites). In pretty much all cases updates have been available for the software in question for months, but haven't been installed.

    If people just kept their software up to date and used strong passwords, there would be a hell of a lot less security breaches.

    In quite a few cases I find the attackers have been inside the machine for months, and the server owners only became aware when they got a big bandwidth bill, or their site seemed slow. If you're storing any data on your users (email addresses or even worse credit card numbers) then you really need to have top-notch security.
     
    forkqueue, Apr 21, 2006 IP
    poseidon likes this.
  6. dfsweb

    dfsweb Active Member

    Messages:
    1,587
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    88
    #6
    Hacked: No
    SMAM Attached: Yes, and quite often
     
    dfsweb, Apr 21, 2006 IP
  7. daredashi

    daredashi Well-Known Member

    Messages:
    667
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #7
    one of my server was hacked last year. it was very smart hack.
    hacker monitored live chat sessions of web host provider and got login details.
    he created backdoor before i hardened server.
    then about 4 / 5 months he didn't do any thing and then started brutforce attacks to others. he had disabled logs, changed many serverces including ps, top, pine, ls etc.

    lesson learned :- never use chat support of web host and never use plain password auth. setting up accesskey / ip based auth is good way.
     
    daredashi, Apr 22, 2006 IP
  8. jsjb10

    jsjb10 Peon

    Messages:
    122
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Hacked.. never however as people have said before spamming is a problem
     
    jsjb10, Apr 22, 2006 IP
  9. ahpeg

    ahpeg Peon

    Messages:
    71
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    yes....suddenly all my database disappear, don know what happen. when i go check phpmyadmin, all database has been delete....damn the hacker...don know how they do tat.
     
    ahpeg, Apr 23, 2006 IP
  10. ronnyb

    ronnyb Well-Known Member

    Messages:
    856
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    170
    #10
    I once got hacked, but that was on a non-updated version og PHPNuke, and the hacker was kind enough to only change the index page... but he gotme scared for a while...
     
    ronnyb, Apr 23, 2006 IP
  11. Hanthunius

    Hanthunius Peon

    Messages:
    26
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I'm more afraid of click bombing .:eek:
     
    Hanthunius, Apr 23, 2006 IP
  12. wheel

    wheel Peon

    Messages:
    477
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Three times in about 6-7 years. All as the result of stupid script problems (i.e., my fault).

    First time, I was using some program like formmail. Gawd, that was a lot of years ago. Anyway, the program would relay email if it received a properly formed input. Took forever to figure this out, they burned 10's of gigs of bandwidth until we figured it out. This was back when bandwidth was really expensive. No access to server though, all they were doing was calling a web page.

    Second time, I woke up to find a bunch of my hosting accounts were reset. Turns out I'd left the 'setup' directory on the server. Running the setup program let them reset the userid/password. Didn't get them anywhere other than into my content management system, but still a bit scary. Thank goodness for proper backups! A quick restore of my database files, delete the setup directory and done.

    Third time I was guilty of running an older copy of phpBB. THis is back when phpBB was getting comprimised routinely. A hacker came in and all they did was post using my user id a post titled 'you've been hacked' with a post saying 'please upgrade your version of phpbb'. No damage other than that.

    I suspect this type of hack is by far the most common, rather than someone actually getting into root or command line access. Never had that happen.

    Now I make sure I know what all the processes are on my machine. Only ssh access allowed to the server by me and my developer. Firewalled only the ports I need are opened. And I update at least once a week from one of my distro's mirrors. And clean up unused programs routinely. Other than that, not sure what else can be done for a regular joe running their own server.
     
    wheel, Apr 30, 2006 IP
  13. tanfwc

    tanfwc Peon

    Messages:
    579
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #13
    I have been securing phpBB and ensure that their board stay up to date. Once I managed to hack into a local board, the data have been build up for years. So in order to prevent other hackers coming in to delete their data, I disable their board and drop a email to the webmaster.

    After which, the webmaster thank me. :)
     
    tanfwc, May 2, 2006 IP
  14. Mia

    Mia R.I.P. STEVE JOBS

    Messages:
    23,694
    Likes Received:
    1,167
    Best Answers:
    0
    Trophy Points:
    440
    #14
    Have you tried the Fudge Sticks? Holy crap! I downed a whole box while posting back and forth with AnthonyCEA recently. They are addictive...


    Someone tried to hack me with an axe once. I axed them not to do it anymore.:rolleyes:
     
    Mia, May 2, 2006 IP
    GTech and TechEvangelist like this.
  15. rahulkr

    rahulkr Well-Known Member

    Messages:
    966
    Likes Received:
    86
    Best Answers:
    0
    Trophy Points:
    120
    #15
    so many times, still i have few sites to restore
     
    rahulkr, May 5, 2007 IP
  16. doga

    doga Well-Known Member

    Messages:
    822
    Likes Received:
    29
    Best Answers:
    0
    Trophy Points:
    148
    #16
    Not yet i hope not in future too :)
     
    doga, May 5, 2007 IP
  17. MD.45

    MD.45 Peon

    Messages:
    109
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #17
    I have had 2 site's hacked, where they have just changed the index page. Luckily nothing server side *touches wood*
     
    MD.45, May 8, 2007 IP
  18. monger

    monger Guest

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #18
    Yes ive had databases hacked, control panels everything. Not a nice feeling at all...
     
    monger, May 9, 2007 IP
  19. Dubz

    Dubz Peon

    Messages:
    1,859
    Likes Received:
    156
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Dubz, May 9, 2007 IP
  20. trichnosis

    trichnosis Prominent Member

    Messages:
    13,785
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    300
    #20
    yes , i have been hacked before on a shared hosting after that i'm not using shared hosting for my main sites
     
    trichnosis, May 9, 2007 IP