Dynadot .com Transfer Sale โ€” only $10.49, coupon COMSUMMER26

My site hacked

Namecheap AuctionsNamecheap Auctions
SpaceshipSpaceship
NamecheapNamecheap
Watch

paaaaaaaaaa

Established Member
Impact
6
How on earth has somebody managed to hack my site and change the header image from saying freshervisions to say Ya, Krevedko. It uses exactly the same font!!
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
It's hard to tell without more info. Perhaps you could put your site in your public profile?

Edit: Sorry, being slow; http://www.freshervisions.com/

However they've done it, they just seem to have overwritten your /images/top-head.gif with their own version.
 
Last edited:
0
•••
Yeah I'm fairly amazed. I have absolutely no clue how they could of possibly done it. My closest guess would be that it hasn't been done by a single person spending time on it. There must have been some sort of script involved like a screen reader that can recognise a font and also the colours then edit an image accordingly. Then there would be the issue of overwriting the file. I have got my images folder set so it's not writeable.

However I have been procrastinating on actually updating my site so here is that little push for me to actually do it.

p.s. I believe the text is russian. Though I don't know what it says, could it be a name?

EDIT:
Well I just noticed that I gave them too much credit. They clearly have just got access to my server. I double checked and the font is not the same as the original. They have also took time to write "looser" after my name in places. Which must be another russian word because I have no idea what it says :)
 
Last edited:
0
•••
There are a lot of ways of hacking into a site. Some can be through sophisticated tools and expertise. But there are many admin/network tricks and hacking tools known (eggdrops, scripts in the warez sites, etc.) that many can actually download and use, including brute-force password dictionaries that lets programs try thousands of words and combinations for the username/password in your site/hosting account, and some of these do get through. (That is, assuming you have a fairly hard to guess password; since in many cases easy or unchanged default words in passwords are a way in for some cases).

Another thing you might want to consider is your web host. If it's in a shared account for example, and another user in the same server as you is able to enter your site from the server itself (such as via SSH if it hadn't been plugged or made secure by the web host).

A few years back for example, I was amazedwhen I tried using SSH (or was it Telnet) to get to the command line of my server (in a shared environment!), and went out of my account's subdirectory and reached the root directory, able to see other accounts' directories and actually entered them! Obviously I didn't do anything but I know I'd have easy changed filenames and overwrote the pages and permissions if I wanted to. Emailing the hosting provider didn't help, and so I quickly got out of there (my account) and moved my site, lest another user come into my own site with less than noble intentions.

Point is, these things happen and these or a thousand other factors can let people enter your site, so you'd do good to check up on possible areas that can go awry.
 
0
•••
You don't even need SSH access on some hosts.
On my last host, I was able to access the root dir, though I couldn't do much.
I informed my host and they locked the directory down.
Where there's a will, there's a way.

PS your site is down for me :s
 
0
•••
Well I found out how they gained access. It was through an upload script allowing them to upload a php script called phpremoteview (basically a php file manager). They where able to edit files via this. My fault really, I should of made my upload directory disable any scripts running.

Anyway now I have the i.p address and date and time of when this person was doing it so I have decided to report them. I have done a ip lookup which guides me to this site http://www.netfort.net/.

What would I do next to report them? Shall I just email that site or are there better ways?
 
0
•••
lol... firstly translate what is said :P

and find a way of reporting to the ISP ;)

any professional hacker would have cleared the logs before leaving.

But be prepared to be disappointed, some countries have very lax rules on hacking
 
Last edited:
0
•••
just comes to show you that with such scripts, you don't really need professional hackers to get into a site's many possible holes.

@paaaaa: Good to see you've seen the source and at least that's a good set of first steps to take to rectify the problem. Thing to do now is try to find (and close) any possible holes.
 
0
•••
I use Acunetix Web Vulnerability Scanner, to find all the "holes" in my sites, its a bit over sensitive, but helps non the less ;)
 
0
•••
Seems fixed now...
 
0
•••
Even my site was hacked by a turkish hacker. He hacked the mysql server and changed the data. So I moved my site to a new host. Now no problems till now.
 
0
•••
Somehow he probably managed to figure out your SQL password and then changed whatever he wanted. At least he didn't do any more damage. You should report this immediately to your host and your ISP too.
 
0
•••
Appraise.net
Escrow.com
Spaceship
Domain Recover
CryptoExchange.com
Catchy
URLs.com
NameFit
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back