Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 28-08-2008, 06:02 PM   #1 (permalink)
Alpha Geek
 
Maverick340's Avatar
 
Join Date: Mar 2004
Posts: 635
Default Website Got Hacked


I recevied an email today from RSA saying that my server had some fraud pages. I pointed to those pages and it was true. There were fake login pages to Novascotia Bank and Abbey
I deleted those pages but am now wondering how was the security breach took palce. Absolutely no one knows my password and anonymous ftp was off. There was also no FTP traffic log. I however saw lots of 404 HTTP requests from cetain IP addresses.
This is what i could find : http://paste2.org/p/66817 | http://paste2.org/p/66818 | http://paste2.org/p/66820

Also there were tons of unresolved IP address that had consumed bandwitdh in excess of 10megabytes in the last 10 days.

I am pretty new at all this so please help me out. My website address is fudge dot co dot in
__________________
You and Me forever be ...
--
PSpwned
Maverick340 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 28-08-2008, 07:23 PM   #2 (permalink)
eWebGuru
 
ahref's Avatar
 
Join Date: Mar 2006
Location: Dehradun
Posts: 427
Default Re: Website Got Hacked

Probably the script you are using may contain php shell, also ensure to give 755 or less permission to your files and folders.
__________________
Windows and linux hosting at http://www.ewebguru.com
Get $50 per blog post PM me for details.
ahref is offline  
Old 28-08-2008, 07:46 PM   #3 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: Website Got Hacked

Is there any web based upload system?
And btw do you trust your webhost?
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 28-08-2008, 10:00 PM   #4 (permalink)
PhotonAttack
 
DigitalDude's Avatar
 
Join Date: Oct 2007
Location: Chennai
Posts: 1,280
Default Re: Website Got Hacked

do you have SSH access to the server ?? if yes it might have been compromised by brute force attacks (which was also attempted in my server)

change your root password and also the SSH port from the default 22 to some other port


it might not be this problem alone.. i'm saying cos this is a common problem...

_
__________________
In a time of universal deceit, telling the truth is a revolutionary act - George Orwell

|| तमसो मा ज्योतिर्गमय ||
DigitalDude is offline  
Old 29-08-2008, 12:19 AM   #5 (permalink)
Alpha Geek
 
Maverick340's Avatar
 
Join Date: Mar 2004
Posts: 635
Default Re: Website Got Hacked

OKay after spending close to 8 hours on it i have some answers. fudge is a simple no frills non tech blog. The 'hacker' created a folder iamges in my public_html foder and pur some php script in it. Name of the script is c99 v0.0.1 SYN-MOD [SYNSTA]
Googling threw up some light on this, seems like a script that has been doing rounds. I deleted those files, removed all other traces of fake login pages etc. I downloaded the source code of the malicious script and also the fake login pages. They do contain some email IDs. I was wondering if o could sumbit them somewhere to help stop phising and web forgery. Also i upgraded the blog from 2.6 to 2.6.1
I want to know if i can do something to protect myself from such attacks. I am still confused how and why was i attacked :-/
__________________
You and Me forever be ...
--
PSpwned
Maverick340 is offline  
Old 29-08-2008, 01:10 AM   #6 (permalink)
Broken In
 
mad_max's Avatar
 
Join Date: Jul 2008
Posts: 131
Default Re: Website Got Hacked

forget the why bro concentrate on how my 2 bits of input lol
mad_max is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mac OS X Hacked - Vista SP1 Hacked – Ubuntu Linux Survives Unscathed CadCrazy Technology News 38 04-04-2008 12:45 PM
how do i avoid getting my website hacked? *GandaBerunda* QnA (read only) 5 17-12-2007 04:17 PM
HACKED: Maharashtra government website slugger Technology News 7 19-09-2007 02:54 PM
IE 6 Hacked, opera also hacked, plz help!!!! Andyiz Software Q&A 6 08-11-2005 04:11 PM

 
Latest Threads
- by abhidev
- by clinton

Advertisement




All times are GMT +5.5. The time now is 06:31 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2