Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 18-09-2008, 12:18 AM   #1 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Identify a hacker


Hi all
My site was taken down today
I have temporarily redirected my site to my blog. I was going through the logs of my site to see how the hack was successful. I am enclosing the same in this post.
Any analysis and advice will be much appreciated. I thought this one IP looked suspicious 78.183.221.32
Will check back for your replies tomorrow morning.
Goodnight
Attached Files
File Type: zip logs.zip (4.2 KB, 14 views)
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-09-2008, 05:49 AM   #2 (permalink)
Wandering In Tecno Land
 
Ecko's Avatar
 
Join Date: Feb 2005
Location: 127.0.0.1
Posts: 724
Default Re: Identify a hacker

Unable to download logs
Achieve Corrupt
Seems to me a job of windows fan
__________________
Born in Windows Die In Linux © 2009-10 All Rights Reserved.
Learn Linux : www.linoob.com (Official WebSite)
Ecko is offline  
Old 18-09-2008, 07:24 AM   #3 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Re: Identify a hacker

Ok I have uploaded the logs again

http://www.mediafire.com/?n2lo5zettzb
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Old 18-09-2008, 10:09 AM   #4 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: Identify a hacker

Did you check your folder and file permissions? Is the joomla15 dir and index file writable by non-privileged users?

Did you perform a recent upgrade?
-There could be a fair possibility that at the end of the upgrade process, the file permissions were not changed and left vulnerable to attacks.

Do you have the recent version(of main joomla as well as modules) with all security fixes?

Have you seen if some others using the save version(exactly as yours) have been defaced?

It could also be a server security issue!(in that case, other sites hosted on the same server as yours are also at risk! so report the mater to your webhost immediately!)

Also, finding IP is not enough as they use proxies and are masters is cleaning their traces!
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 18-09-2008, 01:36 PM   #5 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Re: Identify a hacker

Quote:
Originally Posted by rohan_shenoy View Post
Did you check your folder and file permissions? Is the joomla15 dir and index file writable by non-privileged users?
I installed with default permissions on the server. I did not have to chmod anything

Quote:
Originally Posted by rohan_shenoy View Post
Did you perform a recent upgrade?
-There could be a fair possibility that at the end of the upgrade process, the file permissions were not changed and left vulnerable to attacks.
No

Quote:
Originally Posted by rohan_shenoy View Post
Do you have the recent version(of main joomla as well as modules) with all security fixes?
Yes

Quote:
Originally Posted by rohan_shenoy View Post
Have you seen if some others using the save version(exactly as yours) have been defaced?
Don't know. See I have three domains on the server, one points to the root of my account, and the other to subfolders containing the data. Curiously, the files in the folder which points to neville.in was not touched, except its feedback form, which is linked to a php file?? It is online right now. May I point out that I had a forum on phpbb which I set up two days back exactly as they have mentioned in their instructions, and a Joomla site which has been around for a month or so.

Quote:
Originally Posted by rohan_shenoy View Post
It could also be a server security issue!(in that case, other sites hosted on the same server as yours are also at risk! so report the mater to your webhost immediately!)
I have, and it's now twelve hours up and no response. In fact I just redirected my address from cpanel as I did not want to disturb anything there.

Quote:
Originally Posted by rohan_shenoy View Post
Also, finding IP is not enough as they use proxies and are masters is cleaning their traces!
Yes you're right

Thank you for your time
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"

Last edited by NucleusKore; 18-09-2008 at 01:37 PM. Reason: Automerged Doublepost
NucleusKore is offline  
Old 18-09-2008, 02:42 PM   #6 (permalink)
हॉर्न ओके प्लीज़
 
victor_rambo's Avatar
 
Join Date: Sep 2007
Posts: 1,493
Default Re: Identify a hacker

phpBB? phpBB is not that good at security issues. There are have been numerous instances of phpBB boards getting hacked! I can't say for sure but there is a possibility.
__________________
विक्टर रॅंबो - चाणकया प्रभावित व्यक्ति

गीक होना माँगता
victor_rambo is offline  
Old 18-09-2008, 06:00 PM   #7 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Re: Identify a hacker

Is there any other OSS alternative better than phpBB? Joomla too? If this is the case I'll find myself back with plain old html
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
Old 18-09-2008, 06:47 PM   #8 (permalink)
The Black Waltz
 
Join Date: Apr 2008
Location: The Shed
Posts: 1,511
Default Re: Identify a hacker

Wordpress is better than plain HTML!!!!
__________________
#krow @ irc.freenode.net
Cool Joe is offline  
Old 19-09-2008, 07:37 PM   #9 (permalink)
TheSaint
 
NucleusKore's Avatar
 
Join Date: Jun 2004
Location: Antigua
Posts: 3,447
Default Re: Identify a hacker

Quote:
Originally Posted by rohan_shenoy View Post
Have you seen if some others using the save version(exactly as yours) have been defaced?
Many hacked by same Turkish fellows, I checked in Joomla! forums
__________________
http://www.neville.in
http://www.linuxrocks.in
"The Future Is Open"
NucleusKore is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Uniquely Identify your PC rajesh_nk22 QnA (read only) 10 20-11-2007 05:23 PM
please identify this game . . rajasekharan Gamerz 18 07-02-2007 09:52 AM
Identify USB 1.1 or USB 2.0 mohanty1942 Peripherals 9 18-02-2006 12:14 AM
how to identify DDR400 RAM harshagarwal QnA (read only) 3 24-08-2005 12:21 AM
How to identify??????? q3_abhi QnA (read only) 2 26-07-2005 10:48 PM

 
Latest Threads
- by topgear
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 06:04 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2