sites hacked... plz help

Discussion in 'Security' started by williamsweb, Sep 17, 2009.

  1. #1
    Hi
    my sites got hacked
    www.ewebpets.com and other blogs and sites on that hosting account..

    The main parked site is ok... also one of the blog is ok..
    rest around 10 wordpress blogs and 2 phpld directories are hacked..

    I see only index file changed everywhere... what else could be the problem?
    what to do now?
    why it happened :eek:
     
    williamsweb, Sep 17, 2009 IP
  2. kambing

    kambing Active Member

    Messages:
    461
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    80
    #2
    you are not the one

    http://www.google.co.id/search?hl=id&client=firefox-a&rls=org.mozilla:en-US:official&hs=9X9&q=Powered++by+++Dr.Dang3r&start=10&sa=N
    Code (markup):
    
    http://www.google.co.id/search?hl=id&client=firefox-a&rls=org.mozilla:en-US:official&hs=SFU&q=Hacked+By++Dr.Dang3r&start=0&sa=N
    
    Code (markup):
    I think your server is not safe and secure

    
    http://www.zone-h.org/archive/defacer=Dr.Dang3r
    
    Code (markup):
     
    kambing, Sep 17, 2009 IP
  3. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #3
    oh,, what to do now?
    I already sent mail to my web hosting
     
    williamsweb, Sep 17, 2009 IP
  4. kambing

    kambing Active Member

    Messages:
    461
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    80
    #4
    Just waiting respons from your webhosting support..
    :)

    Hope your problem resolved A.S.A.P
     
    kambing, Sep 17, 2009 IP
  5. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #5
    I see only index.php is changed on all domains..
    just replacing this is all OK?
    could there be infection of other files? how to check then?
     
    williamsweb, Sep 17, 2009 IP
  6. geekos

    geekos Well-Known Member

    Messages:
    3,365
    Likes Received:
    50
    Best Answers:
    0
    Trophy Points:
    140
    #6
    it's useless if you replace all the index files because the problem is in your server host. Your webhost should secure their servers.
     
    geekos, Sep 17, 2009 IP
  7. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #7
    its the top hosting - JUSTHOST
    they are saying my ftp password is cracked or someting
    I found few files in one of my addon site
    with encrypted code link lol.php lol1.php, 0d4y xD.php

    can't find anywhere else
    I uploaded the files for you to see. they are just simple text files - no worry for you..

    Also, I see the main parked domain site is ok and 2 more addon sites OK..
     
    williamsweb, Sep 17, 2009 IP
  8. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,825
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #8
    I have seen quite a few cases, where hackers attack a personal computer, steal the FTP info and upload the index files to the victims' computers automatically every day. I guess you need to check if your home computer is safe, then reset your web site and change the password as well as re upload everything again.
     
    wisdomtool, Sep 17, 2009 IP
  9. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #9
    ok will scan my PC...
    Also, i just changed all index.php files of wordpress blogs.. and removed those 3 above suspicious file-- is it all OK?
    and changing cpanel password too.
     
    williamsweb, Sep 17, 2009 IP
  10. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #10
    ok, thanks for the tips. I am following them all..
    I installed wp security plugin also...
    And one more thing..I am confused on
    the main domain index.php was all normal.. also one blog was normal..
    do they do things manually then?

    and other index.php of directories like wpcontent, wpadmin were not changes..
     
    williamsweb, Sep 17, 2009 IP
  11. geekos

    geekos Well-Known Member

    Messages:
    3,365
    Likes Received:
    50
    Best Answers:
    0
    Trophy Points:
    140
    #11
    Ah i think the intruder uses the new WordPress exploit.
    Check http://mashable.com/2009/09/05/wordpress-attack/ for mroe information about the attack.
    "All users are advised to upgrade to the latest version of WP, while those already affected are in for a trying weekend: you’ll likely need to export your all your content with the built-in XML WordPress export, uninstall and reinstall WordPress and re-import the content. It’s a nasty attack that goes all the way into the database, so exporting the database will result in exporting the hacked code too."
     
    geekos, Sep 17, 2009 IP
  12. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #12
    no, the wordpress was latest script 2.8.4
    also, its not only wordpress, phpld was hacked too.
     
    williamsweb, Sep 17, 2009 IP
  13. merlinseo

    merlinseo Well-Known Member

    Messages:
    1,686
    Likes Received:
    54
    Best Answers:
    0
    Trophy Points:
    130
    #13
    Well Friend,

    I have faced this few time's earlier, And when it happens first time we all simply blame host .
    But as I said since now i learnt so i can share my experience

    Its majorly a attack from your own PC, some malware or some app's or some website which you might have surfed they must have downloaded some app/trojan/virus , Now they collect FTP password/username and what they affect worst is index files because they cant access other files because its auto written script so the smart idiot know every one has a index file with any extension

    And you said only index files are corrupted so rest is fine meaning your host is clean.
    First step : Run licensed professional Anti Virus (Norton) and remove all the detected virus/trojans etc
    Second Step : Run Malwarebyte's Anti-Malware(Free version) and remove all malware
    Third Step : If you dont run first two steps then first thing is go and change your FTP/Cpanel pswd using some another PC .

    Fourth Step : Don't use FTP from your affected pc unless step 1 and step 2 are clear or else it will be same problem again

    Hope it helps

    Thanks and Regards,
    Merlin
     
    merlinseo, Sep 19, 2009 IP
  14. williamsweb

    williamsweb Active Member

    Messages:
    2,016
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    75
    #14
    yeh, I scanned my PC with
    Avira AV free
    And Lavasoft Adaware
    Found some trojans with highest risk 10 :eek:
    removed them
    password resetted.
    lets see what happens now

    can't go on another PC
     
    williamsweb, Sep 19, 2009 IP
  15. kambing

    kambing Active Member

    Messages:
    461
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    80
    #15
    AVIRA free isn't your answer..

    Use Avira Premium -> support firewall, antispyware, root kit detection and all protection
     
    kambing, Sep 19, 2009 IP
  16. bluebenz

    bluebenz Well-Known Member

    Messages:
    876
    Likes Received:
    9
    Best Answers:
    2
    Trophy Points:
    138
    #16
    But if you pretty sure that is caused by your pc, then you can blame to the host company.
    I know others site are hosted in my shared hosting too, and if my site is down, then I will check that other websites (which are not mine).
     
    bluebenz, Sep 19, 2009 IP