hacked by ben laden

Discussion in 'Security' started by deemainer, Apr 26, 2010.

  1. #1
    Anyone run into this hacker?

    "Owned by Mr BenLaden Moroco CRAcK3r"

    One of my wordpress installs redirected via htaccess to index.php in subfolder

    I can understand htaccess being changed...its possible wrong permissions left.But to write another php file does that mean he had ftp access?

    Thanks for your advice
     
    deemainer, Apr 26, 2010 IP
  2. extremephp

    extremephp Peon

    Messages:
    1,290
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Hacker is Hacker..! He may Have Got into your Files through some backdoors..!

    WP is getting hacked a lot nowadays..! anyway keep the file permissions as said in the WP guide to have some security for yourself..!
     
    extremephp, Apr 26, 2010 IP
  3. n3r0x

    n3r0x Well-Known Member

    Messages:
    257
    Likes Received:
    4
    Best Answers:
    1
    Trophy Points:
    120
    #3
    Wouldn´t it be better not to use wordpress if it gets hacked a lot these days?
     
    n3r0x, Apr 30, 2010 IP
  4. robyries

    robyries Notable Member

    Messages:
    3,230
    Likes Received:
    51
    Best Answers:
    6
    Trophy Points:
    205
    Digital Goods:
    1
    #4
    what I heard, you should upgrade your wordpress to early version, don't know which one :p
     
    robyries, Apr 30, 2010 IP
  5. p.hall

    p.hall Guest

    Messages:
    26
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    If this is a Windows server, check whether you have disabled WebDAV.
     
    p.hall, Apr 30, 2010 IP
  6. Actaviosan

    Actaviosan Guest

    Messages:
    216
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    To write another PHP file does not mean he has FTP access. He can get it anyhow.
    First, it is possible that he used an exploit for a vulnerability that exists on WordPress. Sometimes a certain vulnerability can enable a "hacker" to include files such as what they call a shell (like c99) that gives them full control on the server. Such as browsing ALL the files even if they're restricted, writing new files, creating FTP users, changing passwords, and accessing all of these sensitive data.
    Check your WordPress security for vulnerabilities.
     
    Actaviosan, May 5, 2010 IP
  7. ryan1918

    ryan1918 Active Member

    Messages:
    668
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    60
    #7
    He could have hacked the server which means if you don't own it you can't do anything about it, only contact the company and tell them to secure there servers much better and check why it was hacked and how.
     
    ryan1918, May 5, 2010 IP
  8. tenev

    tenev Active Member

    Messages:
    322
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    95
    #8
    probably some kid playing with toys, true hackers don't leave their location, nor logs, check apache accesslogs. the better hackers are from the white side and they will make your server more secure and email you instead of hacking whatever they can. after you get his IP, call his ISP :)
     
    tenev, May 5, 2010 IP