1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

How can we be Hacked from 1 page only?

Discussion in 'Security' started by misohoni, Oct 22, 2011.

  1. #1
    I've checked the access logs and users are getting into the site from one .php page...any help or tips guys?
     
    misohoni, Oct 22, 2011 IP
  2. supportex

    supportex Peon

    Messages:
    66
    Likes Received:
    0
    Best Answers:
    1
    Trophy Points:
    0
    #2
    At the recovery time after hack you need stop web-server. If you already know how the intruder entered to the server you need correct this error in the code. Depending on the type of hack you should. Also check server presence of php-shells, trojan horses and etc. In general, make integrity check of your code and server as a whole.
     
    supportex, Oct 23, 2011 IP
  3. Adam Neal

    Adam Neal Peon

    Messages:
    10
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    If you're hosting your site on a (not very secure) shared server, a script kiddie may be using a Perl/PHP shell script to access your files from another site located on the same server - this is the most common senario.
     
    Adam Neal, Dec 1, 2011 IP
  4. JamesZach

    JamesZach Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    If they are getting your site from that one .php pages, make sure its secured to prevent XSS and cross-site scripting attacks.
     
    JamesZach, Dec 6, 2011 IP
  5. misohoni

    misohoni Notable Member

    Messages:
    1,717
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    200
    #5
    Ok cool, not sure what that is though.

    I've got the access logs from the server infront of me, how do I determine successful accesses where do I look?
     
    misohoni, Dec 6, 2011 IP
  6. JamesZach

    JamesZach Peon

    Messages:
    12
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Looks for REQUEST URI that is not normal. Check out the ips from which the access come in .
     
    JamesZach, Dec 6, 2011 IP
  7. misohoni

    misohoni Notable Member

    Messages:
    1,717
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    200
    #7
    Cheers I found out the page and problem via Acunetix
     
    misohoni, Dec 11, 2011 IP