?
"Go to a dos prompt after you started dial up networking type by the way if you don't know what victim.com stands for you are a dumb mother f*cker."
(Chameleon, marc5@earthlink.net)
The full exploit is available. "
If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.
Register Today on DNForum IT'S FREE!Friday got one of my sites hacked. Fortunately they were nice enough to leave tracks on how they did it.
What a bunch of losers!
I got the site fix, then did it again twice, so I think I've got it under control now for the time being.
Here's the exploit, for those interested:
# script name : Wallpaper site 1.0.09
# GoogLe Dork : Powered by EasySiteNetwork
# Vuln : http://www.victim.com/category.php?c...+admin_login/*
#
# Admin panel: www.victim.com/siteadmin/index.php
#
Courteous and Respectful DNForum Member!
Text Link Ads WhyPark.com - Stop Parking Your Domains - Society's Problems - PM me to Post your Opinions
?
"Go to a dos prompt after you started dial up networking type by the way if you don't know what victim.com stands for you are a dumb mother f*cker."
(Chameleon, marc5@earthlink.net)
The full exploit is available. "
It's very easy for some script kiddie to break into a site, particularly with "point and click" exploit code. The message here is stay up to date with the latest patches and fixes.![]()
Get Your Free Membership!
same thing,one of my joomla sites got hacked..., mother*******r
"Tough times never last, but tough people do."
I looked up all the other sites that got hacked. it seems like I was the only one to get my site back up. Couldn't afford to have the site down. Yes I know what victim.com is, thanks for the lovely comment.
Courteous and Respectful DNForum Member!
Text Link Ads WhyPark.com - Stop Parking Your Domains - Society's Problems - PM me to Post your Opinions
heh, victim.com is just the placeholder for the site thats being attacked
http://www.milw0rm.com/exploits/4770
Yes, yes I know!
Courteous and Respectful DNForum Member!
Text Link Ads WhyPark.com - Stop Parking Your Domains - Society's Problems - PM me to Post your Opinions
just to let you know, victim.com is... oh wait, you know, right?
EDIT: on another note, that exploit must affect a lot of sites. I just managed to get the mysql root password (hash) for one site by using a modification of that exploit (and yes, I'll be notifying them)
Linux/variant site?
1. Never install phpBB
2. ps aux|grep -i exe
In above, usr/libexec/ files are normally fine, so ignore those.
3. Check /tmp for gremlins, if found chmod 0
4. check /var/tmp for gremlins, if found chmod 0
Generally, gremlins can easily be identified by doing a 'cat' [filename]
Here's obvious examples of gremlins from my unfortunate experience:
/tmp/b0t.txt
/tmp/ddos.txt
Your mileage will undoubtedly vary, but this is just a 'steering' guide.
Last edited by fab; 01-05-2008 at 01:21 PM. Reason: Automerged Doublepost
Courteous and Respectful DNForum Member!
Text Link Ads WhyPark.com - Stop Parking Your Domains - Society's Problems - PM me to Post your Opinions
If I was able to crack the hash to give me the actual password, and they haven't firewalled mysql access from outside, then I could own their entire database (all product info, admin passwords, customer credit card info in some cases, etc, etc). Potentially very nasty.
I'm not really a hacker, just a guy with a keen interest in web security. I come from a web programming background. I have hacked some tiny little things in the past, nothing serious, nothing destructive, always purely for fun or from boredom. I wouldn't consider myself a hacker in the true sense.
This is not an invitation for a million PMs asking me to hack stuff btw - I get enough offers of "very interesting little jobs" through my website which has the dubious honour of being no.1 on google for "hacking for beginners"... sorry if you were hopeful
If you need a PHP/mySQL coder though...
Yes this is what frightened me!If I was able to crack the hash to give me the actual password, and they haven't firewalled mysql access from outside, then I could own their entire database (all product info, admin passwords, customer credit card info in some cases, etc, etc). Potentially very nasty.
That was not my intention! Is this you http://www.puremango.co.uk/cm_how_to_hack_79.phpThis is not an invitation for a million PMs asking me to hack stuff btw - I get enough offers of "very interesting little jobs" through my website which has the dubious honour of being no.1 on google for "hacking for beginners"... sorry if you were hopeful
Might try you in the future.If you need a PHP/mySQL coder though.
Courteous and Respectful DNForum Member!
Text Link Ads WhyPark.com - Stop Parking Your Domains - Society's Problems - PM me to Post your Opinions
yep, that's me (damn, there goes my "mysterious stranger" plan).
Going to redesign the site soonish. Pretty old design atm. I'll look forward to hearing from you if you've anything I might be helpful with
EDIT: actually, when I say "that's me", the actual main article on that page wasn't written by me (as explained on the page). Just to be clear.
That sucks, glad you found a fix though. I've been hacked quite a few times.
Bookmarks