navigation
a webmaster learning community
     Home    Register     Search      Help      Login    
Sponsors

Shopping Cart Software
Ecommerce software integrated into Frontpage, Dreamweaver and Golive templates. No monthly fees and available in ASP and PHP versions.

Website Templates
We also have a wide selection of Dreamweaver, Expression Web and Frontpage templates as well as webmaster tools and CSS layouts.

Frontpage website templates
Creative Website Templates for FrontPage, Dreamweaver, Flash, SwishMax

Search Forums
 

Advanced search
Recent Posts

 Todays Posts
 Most Active posts
 Posts since last visit
 My Recent Posts
 Mark posts read

Microsoft MVP

 

Hacked

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
Users viewing this topic: none
Printable Version 

All Forums >> Web Development >> Server Issues >> Hacked
Page: [1]
 
abbeyvet

 

Posts: 5095
From: Kilkenny Ireland
Status: offline

 
Hacked - 4/10/2002 17:21:38   
The home page on a site of mine was replaced this evening with a redirect page to a warez resources site. Not much else seems to have been touched, all the files etc are still there.

What can I do to prevent this happening if anything? Is it the fault of the site or the host company.?

It is an unremarkable site - for a childres charity actually. Just plain HTML mainly.

How easily is this done?



Katherine

++++++++++++++++++++++++
www.inkkdesign.com

Women and cats will do as they please. Men and dogs should relax and get used to the idea.
storm

 

Posts: 421
Status: offline

 
RE: Hacked - 4/10/2002 17:31:27   
let the host know, check the server logs and see if there are any clues as to what security hole was exploited and of course have the host patch it or close it.

if they got your site on that host they may have got others.

let us know what happens.

storm..."Someone put forth the proposition that you can patition the lord with prayer, patition the lord with prayer, patition the lord with prayer...YOU CANNOT PATITION THE LORD WITH PRAYER"

(in reply to abbeyvet)
abbeyvet

 

Posts: 5095
From: Kilkenny Ireland
Status: offline

 
RE: Hacked - 4/10/2002 17:58:28   
So it entirely a server issue?

I am sitting here afraid to check the other sites I have with that host. I have contacted them. Thanks.

Katherine

++++++++++++++++++++++++
www.inkkdesign.com

Women and cats will do as they please. Men and dogs should relax and get used to the idea.

(in reply to abbeyvet)
Shirley

 

Posts: 3126
Joined: 1/8/1999
From: Omaha, Ne USA
Status: offline

 
RE: Hacked - 4/10/2002 18:07:13   
out of curiosity is it on windoze or linux/unix

Shirley

Nobody realizes that some people expend tremendous energy merely to be normal.
Money Tree Web Design

(in reply to abbeyvet)
abbeyvet

 

Posts: 5095
From: Kilkenny Ireland
Status: offline

 
RE: Hacked - 4/10/2002 18:14:58   
Apache/1.3.22 (Unix) PHP/4.1.0 FrontPage/5.0.2.2510 on unknown.

From Netcraft.

Katherine

++++++++++++++++++++++++
www.inkkdesign.com

Women and cats will do as they please. Men and dogs should relax and get used to the idea.

(in reply to abbeyvet)
abbeyvet

 

Posts: 5095
From: Kilkenny Ireland
Status: offline

 
RE: Hacked - 4/10/2002 18:22:54   
Strangest thing. Looking at the log files for that site, which I have not done for months, there are THOUSANDS, I mean literallly thousands of referals from this url, which is so unrelated as the be on a different planet and has no links at all to outside the site.

http://www.theoutletsathershey.com/index1a.html

I dunno. Probably unrelated but that url for an outlet store park in Pennsylvania sends more visitors to this site, a local childrens charity in Kilkenny, Ireland, that all other referrers combined. How weird is that?

Katherine

++++++++++++++++++++++++
www.inkkdesign.com

Women and cats will do as they please. Men and dogs should relax and get used to the idea.

(in reply to abbeyvet)
Rian

 

Posts: 1960
From: Lincoln, Nebraska USA
Status: offline

 
RE: Hacked - 4/11/2002 12:11:33   
Hi Katherine!

Did you get this sorted out? I am no #usr/bin Linux guru but I know there was recently a whole bunch of Linux and Apache module security updates. Many plugged holes that would allow root access to the server after some buffer overruns etc.

Check with your host to see if everything is up to date. Also if the server was compromised at the root level there is NO telling what got installed on your server. Could be anything from a "root kit" backdoor to a zombie agent for use in dDos attacks.
SANS and other security orginizations recommended reformatting and reinstalling OS and server from know good media.

Rian

"Designing The Future"
SR Web Creators
www.srwebcreators.com

"What boots up must come down..."

(in reply to abbeyvet)
abbeyvet

 

Posts: 5095
From: Kilkenny Ireland
Status: offline

 
RE: Hacked - 4/11/2002 13:48:41   
quote:
Did you get this sorted out?

Well, Yes and No. I am just moving the site to my new server, so that takes it out of its current place and all will be well once the DNS changes are made.

quote:
Check with your host to see if everything is up to date


Huh!! And climb Mt Everest on all fours pushing a pea with my nose.

Sorry to be cynical. Did I contact them? Yes I did. Did they reply to me? No, they didn't.

Do you know who they are, the useless shower of @%&£€*~#s, Rian? Yes, you do.

I will not name them publically. YET.



Katherine

++++++++++++++++++++++++
www.inkkdesign.com

Women and cats will do as they please. Men and dogs should relax and get used to the idea.

(in reply to abbeyvet)
caywind

 

Posts: 1479
From: USA
Status: offline

 
RE: Hacked - 4/11/2002 14:36:41   
could this be a probe...portscan...
quote:
Strangest thing. Looking at the log files for that site, which I have not done for months, there are THOUSANDS, I mean literallly thousands of referals from this url, which is so unrelated as the be on a different planet and has no links at all to outside the site.

http://www.theoutletsathershey.com/index1a.html




I'm thinking that maybe there is a store there that has a system that is accessed by an employee, who then uses that to try to gain access to servers...

<spellcheck> </spellcheck>

(in reply to abbeyvet)
Rian

 

Posts: 1960
From: Lincoln, Nebraska USA
Status: offline

 
RE: Hacked - 4/11/2002 15:09:31   
quote:


Do you know who they are, the useless shower of @%&£€*~#s, Rian? Yes, you do.

I will not name them publically. YET.



Aaarrrggghhhh...!!! I was afraid that would be your reply!! I guess I will just have to expedite moving all my sites..... Will join you in naming "them" publicly soon as I get my sites moved!
We'll, Then again.... Maybe "They" will sue me for complaining about their utter lack or service.... (See my post in the Lounge!)

Rian

"Designing The Future"
SR Web Creators
www.srwebcreators.com

"What boots up must come down..."

(in reply to abbeyvet)
caywind

 

Posts: 1479
From: USA
Status: offline

 
RE: Hacked - 4/12/2002 11:06:02   
wow, lot of "move all my sites" going on here. I just say that cause I'm in the process of "moving some sites". Please tell us the secret soon so we don't end up with more sites to move. I've seen sites that attempt to rate the ISP's, but they don't seem to be very up to date... There are a lot of posts here asking about hosting, maybe we could have a poll, and then the results could be displayed for everyone. That way we wouldn't be endorsing or belittling any companies, just posting the aggregate opinions of some experienced webmasters...

I moved ISP's based on a post I made in these forums and I have no qualms about saying it was AIT. Anytime three web people (who I hold in high regard) say that they bailed on an ISP, then I'm outa there.

<spellcheck> </spellcheck>

(in reply to abbeyvet)
Page:   [1]

All Forums >> Web Development >> Server Issues >> Hacked
Page: [1]
Jump to: 1





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts