Hackers... i've been fighting them all week..

Discussion in 'General Chat' started by tcnetspace, Feb 12, 2008.

  1. #1
    Hello everyone.

    This week i recently had all my index files replaced with some hacker page.. I was rather disappointed to say the least.. i also found out that there is an organization turk-h.org.. that find it amusing to hack as many sites possible only to be listed as top hacker.. ANyway, i didn't know how they were getting in but apparently i loaded a public script that was hacked and this gave access to the bastards! Anyway, that script is long gone now.. i hope to god i have all my bases covered... anyone else run into this and might have further suggestions for me to keep the hackers away?

    Much appreciated.
    Tim.
     
    tcnetspace, Feb 12, 2008 IP
  2. live-cms_com

    live-cms_com Notable Member

    Messages:
    3,128
    Likes Received:
    112
    Best Answers:
    0
    Trophy Points:
    205
    Digital Goods:
    1
    #2
    1. Don't use bad scripts.
    2. Check that they didn't leave one of their own scripts on your server to gain remote access later.
     
    live-cms_com, Feb 12, 2008 IP
  3. jmhyer123

    jmhyer123 Peon

    Messages:
    542
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    0
    #3
    use different passwords for ftp, sql, email, etc. so they don't have access to all of them if they only get access to one ;)
     
    jmhyer123, Feb 12, 2008 IP
  4. micksss

    micksss Notable Member

    Messages:
    4,427
    Likes Received:
    268
    Best Answers:
    1
    Trophy Points:
    285
    #4
    What was the script you used that is in question?
     
    micksss, Feb 12, 2008 IP
  5. Stroh

    Stroh Notable Member

    Messages:
    3,482
    Likes Received:
    292
    Best Answers:
    0
    Trophy Points:
    200
    #5
    lol I've had them hack me once. SenqRonize or some idiots like that... turk-h.org is the turkish hacking center which was left behind after I tracerouted to that. I knew what to do though, take that site and its IP and ban it, that way it wouldn't count when the script tries to checks if its a valid hack or not.
     
    Stroh, Feb 12, 2008 IP
  6. tcnetspace

    tcnetspace Peon

    Messages:
    230
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    It was hotscripts ... lesson learned.. Apparently there is a back door in that script.. they created a shell access.. so i was told..

    live-cms, i have many scripts loaded.. is there an easy way to spot a script they would have installed??
    T.
     
    tcnetspace, Feb 12, 2008 IP
  7. live-cms_com

    live-cms_com Notable Member

    Messages:
    3,128
    Likes Received:
    112
    Best Answers:
    0
    Trophy Points:
    205
    Digital Goods:
    1
    #7
    Maybe your FTP program lets you order the files by date modified. I'm not saying that they certainly would have put a backdoor on your server, just that it is safer to check.
     
    live-cms_com, Feb 12, 2008 IP
  8. stylesp

    stylesp Peon

    Messages:
    33
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I suggest changing your password to something very strong. Try not to use beta scripts or scripts you do not know much about. I always try to look up the script to see if it has any vulnerabilities or what not.
     
    stylesp, Feb 12, 2008 IP
  9. tcnetspace

    tcnetspace Peon

    Messages:
    230
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Very well. Thanks for the advice fellas! I will be re-inforcing passwords and having alook for odd files..

    T.
     
    tcnetspace, Feb 12, 2008 IP
  10. SecureWebDev

    SecureWebDev Active Member

    Messages:
    677
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    80
    #10
    One of the best advices ever. Hackers are known to even gain root privalages by this simple human mistake. Also never use the same password for more than 1 site and make sure you use a unique password for all sensitive websites (paypal, bank, etc...)

    Now other advice:
    1) Backup everything and Save your logs so you can see how he hacked you and what he did.
    2) Put the website offline (or change the .htaccess) until things are dealt with in order to prevent further damage.
    3) Make sure to be on top of all updates for your scripts so such things dont happen to you again.
    4) If you want a serious security check get experienced people to help *raises hand* =)

    Hope that helps.
    -Khaled
     
    SecureWebDev, Feb 12, 2008 IP
  11. Raining Blood

    Raining Blood Active Member

    Messages:
    260
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #11
    Beware of backdoor and shell placed on your server.
     
    Raining Blood, Feb 12, 2008 IP
  12. Faint

    Faint Well-Known Member

    Messages:
    663
    Likes Received:
    27
    Best Answers:
    0
    Trophy Points:
    145
    #12
    Google the script name + exploit added after it and see what comes up. It may help you avoid a situation like this in the future.
     
    Faint, Feb 12, 2008 IP