1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

My all sites hacked. Turkish boys replace only Index.html File. Please Help

Discussion in 'Security' started by host_planer, Feb 26, 2007.

  1. Your Content

    Your Content Banned

    Messages:
    1,096
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    0
    #21
    I have seen many sites hacked by those Turkish guys and I believe the problem is a database vulnerability via cpanel :rolleyes:
     
    Your Content, Mar 18, 2007 IP
  2. funtoosh

    funtoosh Active Member

    Messages:
    415
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    60
    #22
    it's not a cpanel or database vulnerability, but it's php cross-script vulnerability and the only solution is mod security, as you can't control scripts of all the users or keep monitoring scripts of 100ds of users on your server who is doing what, use mod security and secure yourself

    Greets
     
    funtoosh, Mar 18, 2007 IP
  3. hashen27

    hashen27 Active Member

    Messages:
    665
    Likes Received:
    39
    Best Answers:
    0
    Trophy Points:
    70
    #23
    Gah, Its a worm that goes through and does it.

    Anything thats 777 and doesn't need to be change it!
     
    hashen27, Mar 18, 2007 IP
  4. miktor

    miktor Peon

    Messages:
    560
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #24
    i just contacted my host, godaddy and i was put through to a stupid girl who did not know what she was doing. when i told her that this attack was worse than the last her reply was "oh really? thats crazy" im not used to this kind of tech support with godaddy since they are usually quite smart and know what they are doing. she created a ticket for advanced tech support and i am waiting for a response from them. i told them about the cross scripting that might have vulnerabilities on other accounts on the shared server so if that is the case they might change my server. last time i was able to just change the index files on the two sites and it got fixed. but this time i have no clue what they did so there goes my site...im deleting my whole joomla installation and hopefully i can salvage a few things from my database. btw who wants to go after those turkish "warriors"???
     
    miktor, Mar 18, 2007 IP
  5. netdeals

    netdeals Guest

    Messages:
    199
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #25
    netdeals, Mar 26, 2007 IP
  6. tavshan

    tavshan Peon

    Messages:
    623
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #26
    i think it is remote file include which scripts you use ? if u need help about security pm me.

    and im from turkey :) whats they sites or nicknames ?
     
    tavshan, Mar 26, 2007 IP
  7. netdeals

    netdeals Guest

    Messages:
    199
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #27
    Safe mode can be turned off using following string by using it in any script.
    This vulnerability effects upto PHP v4.
    ini_restore("safe_mode");

    So if you have old PHP version that aint gonna help.
    Sometime you cant afford to CHMOD every folder to 777. So the best way to stop infiltration is get every thing updated.
     
    netdeals, Mar 26, 2007 IP
  8. TuraN

    TuraN Peon

    Messages:
    1
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #28
    We didnt know that you are Muslim… You are the victim of our protest, cause the server was foreign and we think that you are not Muslim. İf you contact with us we can help you about the security. Because we never hurt a Muslim…

    1923Turk-Grup/TuraN
     
    TuraN, Apr 6, 2007 IP
  9. newrulez

    newrulez Banned

    Messages:
    364
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #29
    set index permission to 777 chmod....n it wil wok again.
     
    newrulez, Apr 23, 2007 IP
  10. TheBusinessMan

    TheBusinessMan Guest

    Messages:
    61
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #30
    thanks for the solution guys this type of thing happening to one of my sites is like my worst nightmare i am glad to see that you guys have spread the knowledge this will help alot of people vauble post guys thanks for this :)
     
    TheBusinessMan, May 18, 2007 IP
  11. nukepuppy

    nukepuppy Peon

    Messages:
    93
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    0
    #31
    most sites are hacked without the need to ever use a password..
     
    nukepuppy, May 20, 2007 IP
  12. miktor

    miktor Peon

    Messages:
    560
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #32
    i think this guy is trying to trick us into setting index permission to 777 chmod so it will be easier to hack
     
    miktor, May 20, 2007 IP
  13. adam1987

    adam1987 Well-Known Member

    Messages:
    714
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    110
    #33
    I got hit by these guys today !!!

    every 777 chmod folder got it !
     
    adam1987, May 29, 2007 IP
  14. randomIntellections

    randomIntellections Well-Known Member

    Messages:
    985
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    180
    #34
    turn on safemode in php.ini . And dont switch if off untill you find the vulnerable script
     
    randomIntellections, May 29, 2007 IP
  15. Clive

    Clive Web Developer

    Messages:
    4,507
    Likes Received:
    297
    Best Answers:
    0
    Trophy Points:
    250
    #35
    No wonder you're red out. This guy was asking for help.

    What scripts are you using on your sites, host_planer?
     
    Clive, May 29, 2007 IP
  16. nickflame

    nickflame Peon

    Messages:
    1,054
    Likes Received:
    56
    Best Answers:
    0
    Trophy Points:
    0
    #36

    I also had problems with this kind of guys, muslim who are so fanatically as to attack anything that's foreign. You know what you should do? on the first page put a picture with a naked woman, they will run like hell and never came back.
     
    nickflame, May 29, 2007 IP
  17. jb007uk

    jb007uk Active Member

    Messages:
    498
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    58
    #37
    I have been hit by these cockroaches in the last few days and they have corrupted most of my websites, I guess because I have a .us domain. Perhaps the U.S. authorities should be tracking them down as I would imagine .us domains are going to be ever increasing targets.

    Their front page gives the address of a portal which is in Turkish and seems to be some sort of hacking site. Anyone interested I can give you the forum address.
     
    jb007uk, Jun 6, 2007 IP
  18. i3luechaos

    i3luechaos Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #38
    Sorry to bump an old thread but they are back up & bigger from what it seems.

    My site got hit this morning. It's just my main index.html file
    Claiming to be Turkish & w/e

    http://www.ruinyou.com
     
    i3luechaos, Jan 6, 2008 IP
  19. i3luechaos

    i3luechaos Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #39
    Figured it out. I feel stupid that it took so long. I have an imageshack clone (picture uploader) on my site. Supposed to be for image files only but they uploaded a php file into it. Dont know if it was hidden in a picture or by itself. That allowed them into my site to change the index.html file.
    If it happens to you, just look at your ftp dates to see what files were edited last. I'm sure it will help.
     
    i3luechaos, Jan 6, 2008 IP
  20. TeamEvox

    TeamEvox Peon

    Messages:
    64
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #40
    These guys are doing this because of the battles between Israel and Arabs/Muslims
    www.arabic-m.com - that's their site, if you wanna see the damage they've caused.

    Btw, they don't have your password, they're doing it from outside of the site...

    Sources: http://israelity.com/tag/hackers/
     
    TeamEvox, May 15, 2009 IP