My site got hacked

Discussion in 'Site & Server Administration' started by Gallito, Nov 9, 2008.

  1. #1
    Hey all, my site http://www.easyonlinemoneymaking.com got hacked, and now it is redirecting to some fake security software website. I realized this after checking the traffic logs for my site and seeing I went from 100+ UV's a day to 1-2 for the past 3 days.

    I don't use any databases for it, and I don't see any meta redirects and my domain isn't set to redirect anywhere else. I don't see how this is happening or how to fix it, any help would be very much appreciated.

    Edit: The issue was they got to my .htaccess and re-wrote it so that it would redirect if any traffic came from search engines. Anyone know how to prevent this from happening in the future?
     
    Gallito, Nov 9, 2008 IP
  2. ryandanielt

    ryandanielt Well-Known Member

    Messages:
    1,797
    Likes Received:
    37
    Best Answers:
    0
    Trophy Points:
    185
    #2
    Works fine for me!
     
    ryandanielt, Nov 9, 2008 IP
  3. sclek

    sclek Banned

    Messages:
    28
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Change your cPanel password (or ftp) to something more secure.
     
    sclek, Nov 9, 2008 IP
  4. Pathan

    Pathan Well-Known Member

    Messages:
    2,196
    Likes Received:
    218
    Best Answers:
    0
    Trophy Points:
    165
    #4
    try to secure your server by installing firewall also install mod_security.
     
    Pathan, Nov 9, 2008 IP
  5. madk

    madk Peon

    Messages:
    141
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Small hacks like this are usually the result of an unsecured server or software on a shared host. I'd check with your provider and make sure they are aware of the issue so they can look into it and plug the holes.
     
    madk, Nov 10, 2008 IP
  6. UncleBun

    UncleBun Banned

    Messages:
    297
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    there could be some loophole .
     
    UncleBun, Nov 10, 2008 IP
  7. wh0

    wh0 Banned

    Messages:
    146
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    somebody may have found a vuln in another site hosted on that server and may have either rooted the server, or the server is unsecure and they may have shell access to all directories.

    Maybe try switching hosts or getting a dedicated server or vps.

    Make sure everything on your site/server is not exploitable and up-to-date (services). You may have been exploited through a script in /cgi-sys/ in which is getting very popular now.

    Other then this, maybe somebody social engineered (pursway) an administrator or user of the server in which giving them access to your files.
     
    wh0, Nov 10, 2008 IP