My first site which hacked

Discussion in 'Site & Server Administration' started by blue_angel, Mar 2, 2007.

  1. #1
    :( Today my first site which hacked what a sad day.

    What you suggest , how I can trace the attack? from a simple cpanel account:(
     
    blue_angel, Mar 2, 2007 IP
  2. Sini

    Sini Peon

    Messages:
    119
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #2
    First of all, what are "symptoms" of the hacking?
     
    Sini, Mar 2, 2007 IP
  3. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #3
    A white page with following message :
    <<F*** You The T*urkύs H***Acker L***uKeNS & D***j KAdir>>>
     
    blue_angel, Mar 2, 2007 IP
  4. Sini

    Sini Peon

    Messages:
    119
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Sini, Mar 2, 2007 IP
  5. codeassist

    codeassist Peon

    Messages:
    267
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Hi blue_angel...If you wish I can secure and pentest your box for you for a small fee. Contact me by PM if interested.
     
    codeassist, Mar 2, 2007 IP
  6. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #6
    Thanks a lot for your response Codeassist Thanks for your offer but it's a share account not server
     
    blue_angel, Mar 2, 2007 IP
  7. codeassist

    codeassist Peon

    Messages:
    267
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Yes but you can take steps to secure your account buddy. Turkish hackers are normally defacers and will deface your website again after hiding the shell script somewhere on the shared server. This can allow companies to lose valuable time that could have been allocated to making revenue.

    Most likely you have an insecure script running.

    Regards,
     
    codeassist, Mar 2, 2007 IP
    blue_angel likes this.
  8. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #8
    Thanks codeassist for your help
     
    blue_angel, Mar 2, 2007 IP
  9. trichnosis

    trichnosis Prominent Member

    Messages:
    13,785
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    300
    #9
    i know 2 think about to prevent hacking .

    1. choose a good cms which has no securiry hole
    2. choose a good hosting provider who cares security
     
    trichnosis, Mar 2, 2007 IP
  10. WebGeek182

    WebGeek182 Active Member

    Messages:
    510
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    95
    #10
    I agree. I've had this happen to my sites in the past that were on a shared host. One of the other accounts, unrelated to mine had an insecure script and the hackers rooted the server. Web site security is a bigger issue every day.

    I'd advise also moving to a more secure host. When you do ask about their security policies and make sure they firewall the server.
     
    WebGeek182, Mar 2, 2007 IP
  11. Sini

    Sini Peon

    Messages:
    119
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #11
    blue_angel : what scripts you are using on your site?
     
    Sini, Mar 2, 2007 IP
  12. inworx

    inworx Peon

    Messages:
    4,860
    Likes Received:
    201
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Be prptected from Shells....I can bet that you will STILL have some shell left on your account which can bring the server DOWN.

    May be rXXX or cXX..they are most common and most powerful as well available these days

    Check every PHP file(which you think not available in original script) by executing it in your browser..the most simple way to find:)
     
    inworx, Mar 2, 2007 IP
  13. pulikuttann

    pulikuttann Banned

    Messages:
    1,839
    Likes Received:
    40
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Just update all the scripts.The problem can be with ur scripts inside ..........
    Let us know the page which get hacked ???
     
    pulikuttann, Mar 2, 2007 IP
  14. tbarr60

    tbarr60 Notable Member

    Messages:
    3,455
    Likes Received:
    125
    Best Answers:
    0
    Trophy Points:
    210
    #14
    I had a Turkish hack on a phpNuke site last year. Based on the logs it was SQL injection. I was able to get into the database and find where they inserted their data (Turkish statements and a redirect to some page "by darby").
     
    tbarr60, Mar 2, 2007 IP
  15. chsajid11

    chsajid11 Banned

    Messages:
    33
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    are u hacked bye turkish guys? if yes they just replace ur index file. upload index file again and set permission to 555. (Read and execute only)
     
    chsajid11, Mar 3, 2007 IP
  16. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #16
    blue_angel, Mar 3, 2007 IP
  17. future

    future Banned

    Messages:
    376
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #17
    call 911 and tell them and Write in every Forum, tell every relative and Put some banner in the streets, go to Tv station to tell them too that My first website got hacked.
    Then you get Pleasure and you start working on 2nd Web!!!
     
    future, Mar 3, 2007 IP
  18. blue_angel

    blue_angel Well-Known Member

    Messages:
    1,174
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #18
    i have over 20 site smart indian singer the post is to report security problem and inform the other user
     
    blue_angel, Mar 3, 2007 IP