Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: sigh, hacked again

  1. #1
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default sigh, hacked again

    I just want to vent a little. The fault really is my own for not having better security, but this past month my site was hacked twice. I looked at the scripts they uploaded to my site. They looked to be using some outdated php.

    Once the scripts were uploaded they scan the site for any other passwords and email them to some address. I then spent nearly all night changing all of my passwords, which they might have gotten access to, like databases or ftp clients.

    Apparently the day I made the changes they uploaded the hacker scripts again, so it looks like I get to change my passwords again. Sigh.

    During the life of my site I have increased the security several times, and have learned several things, but it wasn't enough apparently.

    This time, to increase security further I beefed up my security password with some unicode, created a fake login page and I now record login attempts as well as many facts about each login attempt whether successful or not.

    Maybe this time hackers will have a more difficult time getting in.
    To choose the lesser of two evils is still to choose evil. My personal site

  2. #2
    Join Date
    Nov 2011
    Location
    Buenos Aires
    Posts
    15
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    1- Did you know where is the hack script? Did you check the server logs?
    2- Are you sure all your files are not 777
    3- Check out the process usage..

  3. #3
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default

    how do you check the server logs?
    To choose the lesser of two evils is still to choose evil. My personal site

  4. #4
    Join Date
    Nov 2011
    Location
    Buenos Aires
    Posts
    15
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    Do you have access to the server via ssh?

  5. #5
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default

    My knowledge of these matters is sadly limited, which is probably how I got hacked in the first place. I do not think I have access to Secure Shell (SSH), but I could be wrong.

    I changed allow_url_fopen from on to off.
    To choose the lesser of two evils is still to choose evil. My personal site

  6. #6
    Join Date
    Nov 2011
    Location
    Buenos Aires
    Posts
    15
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    check out this:
    http://www.serverwatch.com/tutorials...-accesslog.htm

    http://httpd.apache.org/docs/2.0/mis...rity_tips.html
    also try to use some firewall in your server, where is located your website ?

  7. #7
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default

    Arizona. The host is GoDaddy.com. website is http://www.animeviews.com in case you have not guessed yet .
    To choose the lesser of two evils is still to choose evil. My personal site

  8. #8
    Join Date
    Nov 2011
    Location
    Buenos Aires
    Posts
    15
    Thanks
    0
    Thanked 1 Time in 1 Post

    Default

    uff Godaddy, did you try to contact the customer support and tell them about your issue?
    Last edited by jscheuer1; 11-01-2011 at 05:08 AM. Reason: Format

  9. #9
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default

    no, but I can do that tomorrow. It is 11:08pm here.

    I was thinking that the fault lay primarily with poor security practices on my part. Here is what I was attacked with: http://blog.ericlamb.net/2010/02/the-horrors-of-c99-php/.
    To choose the lesser of two evils is still to choose evil. My personal site

  10. #10
    Join Date
    Jan 2007
    Location
    Davenport, Iowa
    Posts
    2,385
    Thanks
    100
    Thanked 113 Times in 111 Posts

    Default

    I am getting close to gaining access to SSH. I am also reading the articles you sent me.
    To choose the lesser of two evils is still to choose evil. My personal site

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •