Dirty Hackers

Discussion in 'General Chat' started by Weirfire, Apr 9, 2006.

  1. #1
    Has anyone come across this site before?

    http:// www[dot]zone-h[dot]org/en/defacements/view/id=3547668/

    I just happened to browse one of my sites in development and noticed all the images were missing so I checked the folders and a bunch of them had been moved to another folder and 5 of them have had their permissions changed to 600 and I cant change them back.

    I then checked the stats pages to see where people had been coming from and came across the site above. It appears that people log their attacks on sites and get points for it. Nice!!

    Anyone want to try and hack their site?
     
    Weirfire, Apr 9, 2006 IP
  2. forkqueue

    forkqueue Guest

    Messages:
    401
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #2
    How did the hackers get in to deface your site?
     
    forkqueue, Apr 10, 2006 IP
  3. Weirfire

    Weirfire Language Translation Company

    Messages:
    6,979
    Likes Received:
    365
    Best Answers:
    0
    Trophy Points:
    280
    #3
    I still don't know. I had the write protections as 777, stupidly! :eek:

    Thats probably how but I've changed the passwords just in case.
     
    Weirfire, Apr 10, 2006 IP
  4. cencurut

    cencurut Peon

    Messages:
    257
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Maybe your site has a security flaws in it. Maybe the Operating System or certain application like MySQL, PHP or ASP. Please update to the latest patches or put up some firewall function in your server.

    If your server is a virtual hosting, you should ask you hosting provider to secure your site or you take off your server from the hosting provider.
     
    cencurut, Apr 10, 2006 IP
  5. lindavdz

    lindavdz Peon

    Messages:
    264
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I've had a similar problem.

    I'm using an Opensource CMS called E107. I've recently upgraded from version 0.6x to 0.7., but before I did that I was hacked constantly.

    What would happen is they uploaded a 'picture' that contained a script in it.
    How did they upload it?
    Well, E107's HTML area has a bug. I deleted it and didn't have problems since.
     
    lindavdz, Apr 10, 2006 IP
  6. cencurut

    cencurut Peon

    Messages:
    257
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Yup.. you're right... Many CMS has a bugs here or there.. Some is so critical that make the CMS vurnerable to exploits either the lack of security in the coding or else.

    By the way, if you're implementing the CMS, be sure to update it regularly. Check the CMS forum for any bugs and their patches. Visit regularly these website www.opensourcecms.com for any CMS reviews.

    FYI, phpBB is more prone to attack because these CMS is very buggy... Nevertheless, try Mambo for your CMS.
     
    cencurut, Apr 11, 2006 IP
  7. greatestmj

    greatestmj Guest

    Messages:
    137
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I have heard zone-h.org

    Its a zone for hackers.... where people decide on a site and go n attack it..

    each hackers has its nickname by which they r known!

    They show the sites they hacked and gains reputation...

    There is also Rankings of hackers like who did max hacking and the bigger n difficult hacking gives more points!
     
    greatestmj, Apr 11, 2006 IP
  8. Weirfire

    Weirfire Language Translation Company

    Messages:
    6,979
    Likes Received:
    365
    Best Answers:
    0
    Trophy Points:
    280
    #8
    It's pretty dumb isn't it? How do websites like that get to stay active?
     
    Weirfire, Apr 11, 2006 IP
  9. cencurut

    cencurut Peon

    Messages:
    257
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Maybe the hackers want to be glamour too.. hehehe
     
    cencurut, Apr 11, 2006 IP
  10. karl

    karl Peon

    Messages:
    64
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Alot of hackers have been going after vbullitin boards lately too
     
    karl, Apr 12, 2006 IP
  11. cencurut

    cencurut Peon

    Messages:
    257
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Yup.. you're right. But with VBulletin code is quite a propietary.. maybe it takes time for them to hijack it. If the VBulletin operator always remember to upgrade to the latest patch, then you don't need to worry.
     
    cencurut, Apr 12, 2006 IP