Signs youre being hacked?

Discussion in 'Site & Server Administration' started by rlynch, Mar 1, 2006.

  1. #1
    what are some obvious (and not so obvious) signs to look for?
     
    rlynch, Mar 1, 2006 IP
  2. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #2
    Ugh....you can't login to your own server. :)
     
    RectangleMan, Mar 1, 2006 IP
  3. Caydel

    Caydel Peon

    Messages:
    835
    Likes Received:
    47
    Best Answers:
    0
    Trophy Points:
    0
    #3
    That's a start:D

    Also:

    Pages are changing on you
    long shell connections logged from unknown users

    etc.
     
    Caydel, Mar 1, 2006 IP
  4. studio606

    studio606 Peon

    Messages:
    110
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Huge increases in bandwidth that your web stats cannot account for.
     
    studio606, Mar 1, 2006 IP
  5. casper

    casper Guest

    Messages:
    181
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #5
    check your logs for SQL injections or weird urls like

    bla.com/?page=' OR a=a;
     
    casper, Mar 3, 2006 IP
  6. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #6
    the worst hackers are however those who never cause any damage to content nor ever change password
    just quietly enter and USE your site to set up phishing site ON your domain in an existing subfolder somewhere.
    how to find?
    visually check for files that YOU never made
    there are currently hacker(s) since many months doing exactly that - silently. always using more or less same files uploaded to manage their own site on your site ...
    some however remove these files used after use ended. hence only way to find is by verifying your OLD access log files
     
    hans, Mar 4, 2006 IP
  7. rehash

    rehash Well-Known Member

    Messages:
    1,502
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    150
    #7
    rlynch, who is "you"? your server? your workstation? and what operating system are you running?
     
    rehash, Mar 7, 2006 IP
  8. rlynch

    rlynch Peon

    Messages:
    248
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #8
    linux (redhat) server...apache...mysql db's

     
    rlynch, Mar 7, 2006 IP