1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

I've been HACKED!!

Discussion in 'Security' started by drhfinegifts, Nov 6, 2006.

  1. #1
    What the ??

    I've notified my host regarding this...luckily I backed up the database and website files yesterday because I was trying to implement Google Checkout.

    I am afraid that all my orders since then will be lost if I need to restore the database backup. Not worried about restoring the website files.

    My site is http://www.drhfinegifts.com

    I sent a nasty email to the email given, but I doubt that will matter...
     
    drhfinegifts, Nov 6, 2006 IP
  2. ratzmilk

    ratzmilk Peon

    Messages:
    8
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    You databases and website should be intact. It looks like they have just replaced your index page.

    You may want to remove their page before it gets spidered by the search engines btw. Last thing you need is a Duplicate site penalty.

    You will probably find your host hasn't patched his/your server. I do remember reading on Slashdot about a CPanel patch within the last couple of months.

    This is the problem with Shared hosting. BTW, you hacker could easily be one of the other hosts sharing your sever with you.

    Shared hosting is ok to get started with. But as soon as you can, you should move to a dedicated server or a managed dedicated server if you don't know enough to secure a linux box.
     
    ratzmilk, Nov 6, 2006 IP
  3. drhfinegifts

    drhfinegifts Peon

    Messages:
    368
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Thanks for the tips. I thought maybe it was some sort of redirect or something. Anyway, my host had me change my Cpanel password and reload my webpage. It worked. I don't know what he did, but I'm glad it's fixed.

    Luckily, the hack page was only up for less than an hour!
     
    drhfinegifts, Nov 6, 2006 IP
  4. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #4
    fortunately for your host

    your site is YOUR ONLY YOUR responsibility and your liability !

    hence study all your site
    knwo what oyu do - know what all your SW does
    study access_log files
    search until yoiu find the cause -ä no matter how long it takes - no matter how much it costs
    find hoiles in your site security - and then close them all
     
    hans, Nov 8, 2006 IP
  5. drhfinegifts

    drhfinegifts Peon

    Messages:
    368
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #5
    drhfinegifts, Nov 8, 2006 IP
  6. -Abhishek-

    -Abhishek- Regaining my Momentum!

    Messages:
    2,109
    Likes Received:
    302
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Lol another of those skiddies! Good luck with your site mate!

    Abhishek
     
    -Abhishek-, Nov 8, 2006 IP
    bnts likes this.
  7. bnts

    bnts Well-Known Member

    Messages:
    2,329
    Likes Received:
    310
    Best Answers:
    0
    Trophy Points:
    165
    #7
    Many hacking incidents now a days...Mine also got hacked a a week or so ago...
     
    bnts, Nov 9, 2006 IP
  8. SteveAR

    SteveAR Well-Known Member

    Messages:
    2,692
    Likes Received:
    42
    Best Answers:
    0
    Trophy Points:
    160
    #8
    sorry to hear did you find out where and who it came from?
     
    SteveAR, Nov 9, 2006 IP
  9. Caronet-Hesham

    Caronet-Hesham Peon

    Messages:
    66
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    According to his profile, he just did a mass defacement to a K9hosting server..scary!
     
    Caronet-Hesham, Nov 12, 2006 IP
  10. JesterMagic

    JesterMagic Peon

    Messages:
    179
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I was notified by my internet provider that my sites was hacked yesterday.

    Different hacker from yours but index files where added (but not replaced). Also the date on these files are from Oct 11, 2006 but I noticed that zone-h reported it on November 11th. I didn't know anything was wrong untill I got the email.

    He added files like index.html and default.html but I use php scripting so I never knew about the hack. The index files just contain some text saying it was hacked by blah, blah, blah.

    I am not sure how it happen...

    I run virus scanners nightly and my windows 2003 server is patched up and as far as I know I have php installed correctly.
     
    JesterMagic, Nov 13, 2006 IP
  11. bnts

    bnts Well-Known Member

    Messages:
    2,329
    Likes Received:
    310
    Best Answers:
    0
    Trophy Points:
    165
    #11
    That was the same case they did to my site a few weeks ago http://forums.digitalpoint.com/showthread.php?t=159773

    They placed an index.html file in the main directory, but luckyly no other files were affected.
     
    bnts, Nov 13, 2006 IP
  12. kip

    kip Notable Member

    Messages:
    1,511
    Likes Received:
    69
    Best Answers:
    0
    Trophy Points:
    205
    #12
    I was hacked about 2 months ago, which they somehow used safe_mode to get in. Because my safe_mode was off. They got my whole entire server. 75+ Sites. It was a mess!
     
    kip, Nov 13, 2006 IP
  13. JesterMagic

    JesterMagic Peon

    Messages:
    179
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #13
    I figured out my security hole. It was a TuFat.com script called FlashChat. I removed it.

    The hackers also uploaded a script called phpFileManager 0.9.3 to add their index files.
     
    JesterMagic, Nov 13, 2006 IP
  14. moneymaker1

    moneymaker1 Peon

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    FlashChat? What is the version you have installed? I think if you always up to date with the latest version this shouldn't be happen.
     
    moneymaker1, Nov 13, 2006 IP
  15. bnts

    bnts Well-Known Member

    Messages:
    2,329
    Likes Received:
    310
    Best Answers:
    0
    Trophy Points:
    165
    #15
    oops, I haven't checked yet if the hackers uploaded any files into my directory :( Thanks for this update..I will just have some check now...
     
    bnts, Nov 13, 2006 IP
  16. JesterMagic

    JesterMagic Peon

    Messages:
    179
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #16
    I was a version behind I think. I installed it in July and the bug was discovered in Sept. I do usually try to keep things upgraded but it was on a demo site I hadn't had to time to work on in a while.

    What software do people use to check out what files where modified/added?

    What Virus Scanner, Spy Ware scanner do people use in Windows 2003 server environment?

    I just ran a virus check and checked my logs carefully and did a search for files modified in a certain date range.
     
    JesterMagic, Nov 13, 2006 IP
  17. t2000q

    t2000q Prominent Member

    Messages:
    4,636
    Likes Received:
    192
    Best Answers:
    0
    Trophy Points:
    300
    Digital Goods:
    1
    #17
    I just had a site hacked by this JaMaYcKa dude and I dont run any scripts on my site except simple stuff like google ads is there anything I can do to prevent it from hapening again?
     
    t2000q, May 19, 2007 IP
  18. Day2Day

    Day2Day Banned

    Messages:
    82
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #18
    Was not very hacker safe then lmao!!!!
     
    Day2Day, May 20, 2007 IP
  19. jezza chan

    jezza chan Active Member

    Messages:
    1,488
    Likes Received:
    70
    Best Answers:
    0
    Trophy Points:
    90
    #19
    You just got defaced. You usuallt get in through an unsecured script or a file doesnt have the secure file permissions, dont leave files on 777.

    I found the site where people post the sites they hacked, mine was one of them, just defaced, nothing too bad.
     
    jezza chan, May 20, 2007 IP