1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

my homepage got hacked

Discussion in 'Security' started by bloggernoob, Oct 29, 2007.

  1. #1
    i opened an email from a site directory that i submitted to cause i wanted to check if i was listed or not. i clicked on the link to my homepage and thats when it happened. i was on my homepage five mins earlier and it was fine. when i got sent to my home page it said that i have been hacked and wanted me to email to a hotmail account to get it fixed.

    the domain name of the hacker was ir4dex.org

    does anyone know about anything related to this.

    i called my host and they said that only my index file was changed.

    my host solved the problem but im worried that it will happen again and im wondering what exactly caused this. if it was my local computer or a serverside issue. or ftp i don't know.

    please help.
     
    bloggernoob, Oct 29, 2007 IP
  2. NameyBoy

    NameyBoy Peon

    Messages:
    107
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #2
    If you don't want it to happen to you again make sure your index file is read-only and not writable.
     
    NameyBoy, Oct 29, 2007 IP
  3. bloggernoob

    bloggernoob Peon

    Messages:
    456
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #3
    i changed it to 744 is that good enough?
     
    bloggernoob, Oct 29, 2007 IP
  4. tandac

    tandac Active Member

    Messages:
    337
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    58
    #4
    444 is better. :) It really depends on how the problem occured to begin with.

    Clicking a link isn't enough. There's usually other exploits that come into play.
     
    tandac, Oct 29, 2007 IP
  5. bloggernoob

    bloggernoob Peon

    Messages:
    456
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #5
    has anyone heard of ir4dex.org? it said that was the hacker domain. how do i report the site?
     
    bloggernoob, Oct 30, 2007 IP
  6. NameyBoy

    NameyBoy Peon

    Messages:
    107
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Just do a whois lookup on the domain ir4dex.org and then you will find out who hosts them and then you can report them.
     
    NameyBoy, Oct 30, 2007 IP
  7. microbrain

    microbrain Banned

    Messages:
    1,079
    Likes Received:
    100
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Do you have the backup?
     
    microbrain, Oct 30, 2007 IP
  8. bloggernoob

    bloggernoob Peon

    Messages:
    456
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #8
    yes i do. the issue is taken care of by my host support. but i was just curious if anyone knew who the hackers were. first time somelike that that happened to me so i got pretty riled up
     
    bloggernoob, Oct 30, 2007 IP
  9. toby

    toby Notable Member

    Messages:
    6,923
    Likes Received:
    269
    Best Answers:
    0
    Trophy Points:
    285
    #9
    do you have a writeable folder? what ytpe of site u have? is it image upload site? If it is, please send me the site.
    *i've experienced many type of the kiddy type of hack*
     
    toby, Oct 30, 2007 IP
  10. faizal18

    faizal18 Guest

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    don't come to that website again :-(
     
    faizal18, Oct 30, 2007 IP
  11. bloggernoob

    bloggernoob Peon

    Messages:
    456
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #11
    its actually a flash video site running on wordpress. you can check it out but i warn that its an ADULT site. www.pornonuts.com
     
    bloggernoob, Oct 30, 2007 IP
  12. toby

    toby Notable Member

    Messages:
    6,923
    Likes Received:
    269
    Best Answers:
    0
    Trophy Points:
    285
    #12
    ahh, probably someone is uploading funny script to your upload directory. most likely you need to upgrade your wordpress .
     
    toby, Oct 31, 2007 IP
  13. Armaan143

    Armaan143 Well-Known Member

    Messages:
    1,273
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    160
  14. coolramiz

    coolramiz Banned

    Messages:
    409
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #14
    bad luck as u get hack
     
    coolramiz, Oct 31, 2007 IP
  15. Fash

    Fash Peon

    Messages:
    37
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Check your access logs for mysterious entries. Also, they might have a PHP shell on your site, so look out for that as well.
     
    Fash, Oct 31, 2007 IP
  16. jonimontana

    jonimontana Well-Known Member

    Messages:
    262
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    108
    #16
    yea.. c99 can couse many trubels.. be carfull..
     
    jonimontana, Nov 1, 2007 IP
  17. Martens

    Martens Peon

    Messages:
    126
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #17
    You need some pass protec or etc
     
    Martens, Nov 6, 2007 IP
  18. bloggernoob

    bloggernoob Peon

    Messages:
    456
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #18
    i told my host to upgrade software for me and they did it. so far so good. i did a whois look up of ir4dex.org and its a brazillian site. owner is thallissom de souza dutra. anyway if anyone has more info please let me know. just curious thats all. i don't think they are any major hackers. just some hackernoobs.
     
    bloggernoob, Nov 8, 2007 IP
  19. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #19
    A quick Google tells me much about their activities.

    It looks like they are trying to gain some notoriety by hacking as many sites as they can and claiming credit for them all. It doesn't look like they are doing much more than that but it's impossible to be sure without investigating more deeply. If you have closed the hole they used to get in then you should be fine for a while but I would suggest upgrading everything regularly. It rarely hurts and it frequently helps.
     
    Ladadadada, Nov 9, 2007 IP
  20. Aimshotz

    Aimshotz Guest

    Messages:
    57
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #20
    You won't be able to report them if they're on a swedish host though, all you can do is secure your server and hope they don't do it again.
     
    Aimshotz, Dec 31, 2007 IP