Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Results 1 to 16 of 16

Thread: Got Hacked!

  1. #1
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,887
    Bank
    0
    Total DNF$
    33,887
    Donate  

    Got Hacked!

    Friday got one of my sites hacked. Fortunately they were nice enough to leave tracks on how they did it.

    What a bunch of losers!

    I got the site fix, then did it again twice, so I think I've got it under control now for the time being.

    Here's the exploit, for those interested:

    # script name : Wallpaper site 1.0.09
    # GoogLe Dork : Powered by EasySiteNetwork


    # Vuln : http://www.victim.com/category.php?c...+admin_login/*
    #
    # Admin panel: www.victim.com/siteadmin/index.php
    #

  2. #2
    Devil Dog's Avatar
    Join Date
    Feb 2006
    Location
    Arizona
    Posts
    3,203
    DNF$
    12,929
    Bank
    0
    Total DNF$
    12,929
    Donate  
    ?

    "Go to a dos prompt after you started dial up networking type by the way if you don't know what victim.com stands for you are a dumb mother f*cker."

    (Chameleon, marc5@earthlink.net)
    The full exploit is available. "

  3. #3
    Platinum Lifetime Member
    omosquera's Avatar
    Join Date
    Feb 2006
    Location
    Cali
    Posts
    479
    Blog Entries
    1
    Country

    Colombia
    DNF$
    2,162
    Bank
    0
    Total DNF$
    2,162
    Donate  
    Quote Originally Posted by fab View Post
    Friday got one of my sites hacked. :
    I used to get my sites hacked for using proxies....

  4. #4
    Domainer
    simon johnson's Avatar
    Join Date
    Dec 2005
    Location
    Melbourne, Aust
    Posts
    237
    Country

    Australia Follow simon johnson On Twitter Add simon johnson on Facebook Visit simon johnson's Youtube Channel
    DNF$
    2,385
    Bank
    0
    Total DNF$
    2,385
    Donate  
    It's very easy for some script kiddie to break into a site, particularly with "point and click" exploit code. The message here is stay up to date with the latest patches and fixes.

  5. #5
    Platinum Lifetime Member

    Join Date
    Mar 2006
    Location
    Don't ask..
    Posts
    915
    DNF$
    1,032
    Bank
    0
    Total DNF$
    1,032
    Donate  
    same thing,one of my joomla sites got hacked..., mother*******r
    "Tough times never last, but tough people do."

  6. #6
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,887
    Bank
    0
    Total DNF$
    33,887
    Donate  
    I looked up all the other sites that got hacked. it seems like I was the only one to get my site back up. Couldn't afford to have the site down. Yes I know what victim.com is, thanks for the lovely comment.

  7. #7
    heh, victim.com is just the placeholder for the site thats being attacked

    http://www.milw0rm.com/exploits/4770

  8. #8
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,887
    Bank
    0
    Total DNF$
    33,887
    Donate  
    Yes, yes I know!

  9. #9
    Platinum Lifetime Member

    Join Date
    Dec 2007
    Location
    UK
    Posts
    234
    DNF$
    1,577
    Bank
    0
    Total DNF$
    1,577
    Donate  
    just to let you know, victim.com is... oh wait, you know, right?

    EDIT: on another note, that exploit must affect a lot of sites. I just managed to get the mysql root password (hash) for one site by using a modification of that exploit (and yes, I'll be notifying them)

  10. #10
    Formerly 'aZooZa'
    Dale Hubbard's Avatar
    Join Date
    Jan 2003
    Location
    UK Expat in CN
    Posts
    6,239
    Country

    England Follow Dale Hubbard On Twitter
    DNF$
    3,120
    Bank
    0
    Total DNF$
    3,120
    Donate  
    Linux/variant site?

    1. Never install phpBB

    2. ps aux|grep -i exe

    In above, usr/libexec/ files are normally fine, so ignore those.

    3. Check /tmp for gremlins, if found chmod 0

    4. check /var/tmp for gremlins, if found chmod 0

    Generally, gremlins can easily be identified by doing a 'cat' [filename]

    Here's obvious examples of gremlins from my unfortunate experience:

    /tmp/b0t.txt
    /tmp/ddos.txt

    Your mileage will undoubtedly vary, but this is just a 'steering' guide.

  11. #11
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,887
    Bank
    0
    Total DNF$
    33,887
    Donate  
    Quote Originally Posted by sunja View Post
    EDIT: on another note, that exploit must affect a lot of sites. I just managed to get the mysql root password (hash) for one site by using a modification of that exploit (and yes, I'll be notifying them)
    Oh boy, now that sounds really dangerous. BTW, are you a hacker?

    AZooZa, thanks for the info, however, it's a little over my head. Could you either give a more detailed explained, or I will start Googling.
    Last edited by fab; 01-05-2008 at 01:21 PM. Reason: Automerged Doublepost

  12. #12
    Platinum Lifetime Member

    Join Date
    Dec 2007
    Location
    UK
    Posts
    234
    DNF$
    1,577
    Bank
    0
    Total DNF$
    1,577
    Donate  
    If I was able to crack the hash to give me the actual password, and they haven't firewalled mysql access from outside, then I could own their entire database (all product info, admin passwords, customer credit card info in some cases, etc, etc). Potentially very nasty.

    I'm not really a hacker, just a guy with a keen interest in web security. I come from a web programming background. I have hacked some tiny little things in the past, nothing serious, nothing destructive, always purely for fun or from boredom. I wouldn't consider myself a hacker in the true sense.

    This is not an invitation for a million PMs asking me to hack stuff btw - I get enough offers of "very interesting little jobs" through my website which has the dubious honour of being no.1 on google for "hacking for beginners"... sorry if you were hopeful

    If you need a PHP/mySQL coder though...

  13. #13
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,887
    Bank
    0
    Total DNF$
    33,887
    Donate  
    If I was able to crack the hash to give me the actual password, and they haven't firewalled mysql access from outside, then I could own their entire database (all product info, admin passwords, customer credit card info in some cases, etc, etc). Potentially very nasty.
    Yes this is what frightened me!
    This is not an invitation for a million PMs asking me to hack stuff btw - I get enough offers of "very interesting little jobs" through my website which has the dubious honour of being no.1 on google for "hacking for beginners"... sorry if you were hopeful
    That was not my intention! Is this you http://www.puremango.co.uk/cm_how_to_hack_79.php
    If you need a PHP/mySQL coder though.
    Might try you in the future.

  14. #14
    Formerly 'aZooZa'
    Dale Hubbard's Avatar
    Join Date
    Jan 2003
    Location
    UK Expat in CN
    Posts
    6,239
    Country

    England Follow Dale Hubbard On Twitter
    DNF$
    3,120
    Bank
    0
    Total DNF$
    3,120
    Donate  
    Most of these hacks show up in /tmp.

  15. #15
    Platinum Lifetime Member

    Join Date
    Dec 2007
    Location
    UK
    Posts
    234
    DNF$
    1,577
    Bank
    0
    Total DNF$
    1,577
    Donate  
    Quote Originally Posted by fab View Post
    yep, that's me (damn, there goes my "mysterious stranger" plan ).
    Going to redesign the site soonish. Pretty old design atm. I'll look forward to hearing from you if you've anything I might be helpful with

    EDIT: actually, when I say "that's me", the actual main article on that page wasn't written by me (as explained on the page). Just to be clear.

  16. #16
    Platinum Lifetime Member
    kissedbymysweety's Avatar
    Join Date
    Jul 2006
    Location
    England, UK
    Posts
    86
    DNF$
    487
    Bank
    0
    Total DNF$
    487
    Donate  
    That sucks, glad you found a fix though. I've been hacked quite a few times.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com