1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

I've been hacked....

Discussion in 'Site & Server Administration' started by Notting, Jul 25, 2006.

  1. #1
    All I know is:

    www.nottinghamstudent.co.uk
    SEMrush
    All files have not been deleted though. I think they have just changed the index page.

    ukhost4u.co.uk are being less than helpful - cant get through on the phone wont reply to my emails.

    Sam page shows on the other websites on the account:

    www.theafricangreyparrot.com and www.countrypictureframing.co.uk

    I was in the process of selling www.nottinghamstudent.co.uk for arund the 4500 mark then this happened and fucked the sale up. (coincidence?)

    What should i do?? Does the host have responsibility for security?

    Please help
    Notting
     
    Notting, Jul 25, 2006 IP
    SEMrush
  2. sandossu

    sandossu Guest

    Messages:
    2,274
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Maybe the buyer wants a discount :)

    Things like this happen daily and i`m curious who`s fault is. Yours or host`s?
     
    sandossu, Jul 25, 2006 IP
  3. Notting

    Notting Notable Member

    Messages:
    3,210
    Likes Received:
    335
    Best Answers:
    0
    Trophy Points:
    280
    #3
    I've spoken via MSN to the hacker. Now i've never had much of a problem with MUSLIM's up till now. But frankly I'm chaing my mind - fuck them, let them rot in hell.


    Conversation with Muslim hacker:
    Never give out your password or credit card number in an instant message conversation.

    Jamie says:
    Hi, you hacked my website. I'd like to know why you did this to me?
    says:
    wait half hour please good bye
    Jamie says:
    no - speak to me now

    You have just sent a Nudge!

    says:
    yeah what youo want?
    Jamie says:
    you hacked my website - why?
    says:
    i hacked the HOST thats mean all sites on it
    included yous
    says:
    yours
    Jamie says:
    ok - I dont feel so vicitimised now. Please explain to me why you would do such a thing. Did they annoy you?
    says:
    are you from british?
    Jamie says:
    Yes
    says:
    your army kill and hits our brother in iraq
    that is the reason
    says:
    and i w"ll finish in sha"allah all server british isreal and amaricn
    Jamie says:
    whats that got to do with me.
    Jamie says:
    you want to stop performing terroist acts and we'll stop killing you
    (i was starting to get pissed off - i had phoned the police by this point and they said "contact you ISP" (twats)

    I know it's not all Muslims. But let's face it - most of them are backward as fuck.
     
    Notting, Jul 25, 2006 IP
  4. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,220
    Likes Received:
    778
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Probably explains why your ISP isn't answering... Would want to be working there right now. Those situations show it pays to pay good money for a decent host.

    Sucks man, let me know when you need a good UK host, I can get you a nice deal if paying £200 a month isn't an issue for you.

    I wouldn't piss them off more than they already are, it might not stay with a simple hack.
     
    T0PS3O, Jul 25, 2006 IP
  5. lorien1973

    lorien1973 Notable Member

    Messages:
    12,210
    Likes Received:
    603
    Best Answers:
    0
    Trophy Points:
    260
    #5
    host has a total server backup; I'm sure. Most of them do. Mine does and if my account gets hacked; it'd just restore the version from 24 hours ago or something.
     
    lorien1973, Jul 25, 2006 IP
  6. mad4

    mad4 Peon

    Messages:
    6,989
    Likes Received:
    493
    Best Answers:
    0
    Trophy Points:
    0
    #6
    So have they altered your passwords for ftp and stuff?

    If your domain is registered at another location it might pay to just change hosts and upload your files somewhere else.
     
    mad4, Jul 25, 2006 IP
  7. sandossu

    sandossu Guest

    Messages:
    2,274
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I would change host immediately. Get a well known one, they don`t have problems like that
     
    sandossu, Jul 25, 2006 IP
  8. timw

    timw Peon

    Messages:
    299
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Changing hosts is definitely the way to go :)
     
    timw, Jul 25, 2006 IP
  9. redz

    redz Well-Known Member

    Messages:
    3,096
    Likes Received:
    114
    Best Answers:
    0
    Trophy Points:
    105
    #9
    i have seen a few sites that this guy has hacked, a very messed up way to get back on soldiers who killed their people if we, the webmasters, didnt even go to war... we were on our pc's.
     
    redz, Jul 25, 2006 IP
  10. sandossu

    sandossu Guest

    Messages:
    2,274
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    0
    #10
    he must be crazy or something, he thinks he revenges his country. lol :)
     
    sandossu, Jul 25, 2006 IP
  11. Rouier

    Rouier Banned

    Messages:
    287
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #11
    He's just a script kiddie, he isn't even a real hacker. Real hackers program their own stuff, he just downloads someone elses. Next time your on MSN with him ask him what a buffer overflow is.
     
    Rouier, Jul 25, 2006 IP
  12. tonyiam

    tonyiam Peon

    Messages:
    13
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    why not you change location of your files?
     
    tonyiam, Jul 25, 2006 IP
  13. Notting

    Notting Notable Member

    Messages:
    3,210
    Likes Received:
    335
    Best Answers:
    0
    Trophy Points:
    280
    #13
    OK - Whats happened has happened. Time to leave the politics aside and start rebuilding.

    From what I can gather the hacker has run a script or something like that which deleted all of the index files and replaced them with:

    What you find at this page:

    http://www.nottinghamstudent.co.uk/store/


    One problem in restoring - i do not have access to the website files as they are in Nottingham and I am staying with my parents for two months.

    I have sorted out the first index page by getting the source code from the google cache and simply uploading it:
    www.nottinghamstudent.co.uk

    sorted! - fairly simple because it was static html

    The problem is on this page:

    http://www.nottinghamstudent.co.uk/store/

    a dynamic page from the cubecart script.

    If I just copy the google cache and upload as it is will this work?

    Now...whaty about

    http://www.nottinghamstudent.co.uk/store/admin

    which was not indexed?

    hhhmm...getting tricky now

    Any comments/help/suggestions in getting this sorted will be greatly appreciated.

    Notting
     
    Notting, Jul 25, 2006 IP
  14. mad4

    mad4 Peon

    Messages:
    6,989
    Likes Received:
    493
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Unless you can get the original source code you are screwed. The google cache only has the html output so you can't get any backend stuff.

    Your host might have a backup somewhere. Or you could start again from the basic script.
     
    mad4, Jul 25, 2006 IP
  15. Notting

    Notting Notable Member

    Messages:
    3,210
    Likes Received:
    335
    Best Answers:
    0
    Trophy Points:
    280
    #15
    Thats what i thought.

    Now,

    It seems that the hacker only affected the index.php/html files.

    If i just download a clean index.php/html file and over write the hacked/changed one i may be in business.

    With my forum @ http://theafricangreyparrot.com/African-Grey-Parrot-Community-forum.html

    I think that all of the posts (which I dont want to lose) are in different files. Same with the settings. If i just get a clean index.php file and over write the changed/hacked one i may be ok and not lose all the members/posts on the forum.

    I'll let you know how I get on.

    Notting

    My site was recently hacked and had an SMF forum on it.

    I need to reinstall the forum but want to keep the boards/members/posts. What files do I need to do this?

    I was thinking -

    reinstall the forum and then upload the files containing member profiles and posts etc

    What do ya reckon
    Notting
     
    Notting, Jul 25, 2006 IP
  16. SNap3

    SNap3 Peon

    Messages:
    974
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #16
    How "hacked"?

    What type and version of forum?

    Thank you!
     
    SNap3, Jul 25, 2006 IP
  17. sknydave

    sknydave Peon

    Messages:
    42
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    wow he hacks in the name of Allah
     
    sknydave, Jul 25, 2006 IP
  18. mad4

    mad4 Peon

    Messages:
    6,989
    Likes Received:
    493
    Best Answers:
    0
    Trophy Points:
    0
    #18
    The forum posts will probably be in a database so they should be fine.
     
    mad4, Jul 26, 2006 IP
    sandossu likes this.
  19. SNap3

    SNap3 Peon

    Messages:
    974
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Sorry, I didnt read full thread.
    This dude acting strange, more like a spammer.
    Maybe you should contact the owner of the website hes linking to.

    Good luck mate!
     
    SNap3, Jul 26, 2006 IP
  20. sachin410

    sachin410 Illustrious Member

    Messages:
    6,423
    Likes Received:
    573
    Best Answers:
    0
    Trophy Points:
    410
    #20
    This group is targeting hosting servers all over the net.

    I read about it on two other forums.

    Here is a post from ArticleDashboard forum.

    They are hell-bent on destroying as many sites on western servers as they can. This particular host server (hxxp://hostingfree4life.com ) is yet to recover from the attack.
     
    sachin410, Jul 27, 2006 IP