Have I Been Hacked?

Discussion in 'PHP' started by wierdo, Jul 29, 2008.

  1. duf

    duf Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #21
    I have no ability to run CRON jobs on my host or shell access. All they give you is something called WebShell.

    At this point I am guessing the hack may have been via Wordpress although I had it updated to the latest and greatest version at the time of the hack. (2.61)

    Yes I am disgusted with my hosts unwillingness/inability to do anything to help me recover from the hack.

    I have recovered however via a combination of a month old local back up and some nifty programming by a buddy of mine in Visual Studio C#
     
    duf, Aug 20, 2008 IP
  2. duf

    duf Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #22
    Thanks for the replies btw. To expand on how I recovered, I uploaded my month old back up of my one domain, the biggest one, some 30,000 files. The other affected domains got downloaded locally to my pc. Once they were local I ran my buddies program. It basically looked for the starting and ending pattern of the hack and removed everything in between. I was able to scrub hundreds of html and php files in seconds.

    If someone else runs up against the task of needing to remove code from thousands of files give me a holler and I can hook you up with the program.

    The bad news is I still don't know definitively what allowed the hack to take place. As a precaution I have changed passwords and made back ups of the scrubbed files so I can recover if I get infiltrated again.
     
    duf, Aug 20, 2008 IP