My site hacked again, what should i do

Discussion in 'Legal Issues' started by Dazed_and_confused, Aug 7, 2006.

  1. #1
    Hello,
    my myspace site has hacked once again. This time the hackers left some info about them.

    Their usernames are CoLL1eR & k0pac from http://www.securegb.com .

    This is the second time my site get hacked.

    What can i do?

    Thanx in advance.
     
    Dazed_and_confused, Aug 7, 2006 IP
  2. shamess

    shamess Well-Known Member

    Messages:
    1,127
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    185
    #2
    Find out how they hacked your site from looking at your logs and fix the problem.
     
    shamess, Aug 7, 2006 IP
  3. eddy2099

    eddy2099 Peon

    Messages:
    8,028
    Likes Received:
    568
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Most important thing is to secure your site or server to prevent it being hacked. If a site is hacked, there is always a vulnerability. Since it is MySpace, contact MySpace about it, maybe they have a solution or at least they can be made aware of the situation and hopefully come out with a fix.
     
    eddy2099, Aug 7, 2006 IP
  4. donthate

    donthate Banned

    Messages:
    922
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    0
    #4
    If its a myspace account you mean, change your password , and make sure every URL you enter your password/username into is login.myspace.com etc
     
    donthate, Aug 7, 2006 IP
  5. CoLL1eR

    CoLL1eR Peon

    Messages:
    3
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    We did not hack your myspace. We help people fix security issues on there site. We have nothing to do with myspace..
     
    CoLL1eR, Aug 8, 2006 IP
  6. Dazed_and_confused

    Dazed_and_confused Well-Known Member

    Messages:
    2,071
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    120
    #6
    Not myspace account but myspace resources site.
     
    Dazed_and_confused, Aug 8, 2006 IP
  7. rosytoes

    rosytoes Peon

    Messages:
    230
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #7
    If you are using a script, may be you should contact the script owner so that the holes can be fixed.
     
    rosytoes, Aug 8, 2006 IP
  8. CoLL1eR

    CoLL1eR Peon

    Messages:
    3
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Ahh ok. Please remove the uploader which is yoursite.com/upload.php. That is a big security vuln in those myspace resource sites.. People can upload shells and access your site. Have a nice day.
     
    CoLL1eR, Aug 8, 2006 IP
  9. casper

    casper Guest

    Messages:
    181
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Aaaah, so after all it was just a scriptkiddy that used an exploit to crack.
     
    casper, Aug 8, 2006 IP
  10. Jdog

    Jdog Peon

    Messages:
    267
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Is there a way to limit the uploader only to certain files. Like for the image uploader only allow .jpg of .gif files?
     
    Jdog, Aug 9, 2006 IP
  11. CoLL1eR

    CoLL1eR Peon

    Messages:
    3
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Yes, But make sure you limit php.jpg or php.jpg.jpg because people can change the file extension and upload a shell as an image. You can do that somewhere in your config file.
     
    CoLL1eR, Aug 9, 2006 IP
    danielbruzual and aeiouy like this.