icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » Shared Hosting » I've now been hacked!

Shared Hosting Questions about your shared hosting account.

Reply
 
LinkBack Thread Tools Search this Thread
Old December 20th, 2007, 9:52 PM   #1 (permalink)
Jezebel From Hell..
Comfy Contributor
 
JadedSouls's Avatar
 
Joined in Sep 2004
Lives in Canada, eh?
Hosted on SH131
143 posts
Gave thanks: 7
Thanked 1 Time in 1 Post
I've now been hacked!

.. this just really isn't my week.

Anyone going to my domain now gets greeted with the attached image!

*lol*

oh god!
Attached Thumbnails
ive-now-been-hacked-hacked.jpg  
__________________
[SIGPIC][/SIGPIC]
Jaded Souls | A Haven For Creative Chaos
You're so jaded.. and I'm the one who jaded you!

Server: SH131
Serverload:
JadedSouls is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:23 PM   #2 (permalink)
Registered User
Fresh Surpasser
 
Joined in Dec 2007
Lives in Pennsylvania
Hosted on orange
5 posts
Gave thanks: 0
Thanked 0 times
That reminds me of what happened to my website when it was on a friend's surpass reseller account. This group "hacked" me and left up an index saying "Hey Mr Admin. We Catch You!" and said it was just a warning and that nothing was touched.
Zerxer is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:26 PM   #3 (permalink)
Jezebel From Hell..
Comfy Contributor
 
JadedSouls's Avatar
 
Joined in Sep 2004
Lives in Canada, eh?
Hosted on SH131
143 posts
Gave thanks: 7
Thanked 1 Time in 1 Post
It's annoying as heck, that's for sure
__________________
[SIGPIC][/SIGPIC]
Jaded Souls | A Haven For Creative Chaos
You're so jaded.. and I'm the one who jaded you!

Server: SH131
Serverload:
JadedSouls is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:29 PM   #4 (permalink)
Skittles
Super #1
 
DewKnight's Avatar
 
Joined in Aug 2004
Lives in a space ship
Hosted on dedi
6,806 posts
Gave thanks: 101
Thanked 197 times
Do you know how they did it? What scripts do you run? Were they up to date? Did you use any plugins or modifications with those scripts?
__________________
Mountain Dew Knight
People should not be afraid of their governments. Governments should be afraid of their people.
DewKnight is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:32 PM   #5 (permalink)
Jezebel From Hell..
Comfy Contributor
 
JadedSouls's Avatar
 
Joined in Sep 2004
Lives in Canada, eh?
Hosted on SH131
143 posts
Gave thanks: 7
Thanked 1 Time in 1 Post
No I don't know how they did it at all.. I do run a few plugins/products on the vbulletin but I'm not sure which run scripts or not..
__________________
[SIGPIC][/SIGPIC]
Jaded Souls | A Haven For Creative Chaos
You're so jaded.. and I'm the one who jaded you!

Server: SH131
Serverload:
JadedSouls is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:36 PM   #6 (permalink)
Registered User
Fresh Surpasser
 
Joined in Dec 2007
Lives in Pennsylvania
Hosted on orange
5 posts
Gave thanks: 0
Thanked 0 times
I had a REALLY bad Password at the time (was like qwerty#) but I think what they could've done was found out I had an upload script for images and used it against me since it wasn't secure. I had a program that accesses the upload script in my public /files/ folder which was linked from the main index so they could've found out I had that page through there.

That's what happened with me, anyways. I recently changed my upload script to send it over to ImageShack and delete it off my site right away so I wouldn't have to worry about it. It also makes sure that the file type is some type of image.
Zerxer is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:40 PM   #7 (permalink)
Jezebel From Hell..
Comfy Contributor
 
JadedSouls's Avatar
 
Joined in Sep 2004
Lives in Canada, eh?
Hosted on SH131
143 posts
Gave thanks: 7
Thanked 1 Time in 1 Post
I used to have an upload script, not now.. *lol*


.. I do have a status.php script that I got from here that's there as well
__________________
[SIGPIC][/SIGPIC]
Jaded Souls | A Haven For Creative Chaos
You're so jaded.. and I'm the one who jaded you!

Server: SH131
Serverload:

Last edited by JadedSouls; December 20th, 2007 at 10:43 PM..
JadedSouls is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 10:53 PM   #8 (permalink)
Jezebel From Hell..
Comfy Contributor
 
JadedSouls's Avatar
 
Joined in Sep 2004
Lives in Canada, eh?
Hosted on SH131
143 posts
Gave thanks: 7
Thanked 1 Time in 1 Post
I went and looked via ftp at what was on there and there was a file on there that was put on 8:23pm which was an index.html file which had that black index page on it.

I kept a copy of it, deleted it off the ftp and now my portal page is back again.
__________________
[SIGPIC][/SIGPIC]
Jaded Souls | A Haven For Creative Chaos
You're so jaded.. and I'm the one who jaded you!

Server: SH131
Serverload:
JadedSouls is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old December 20th, 2007, 11:06 PM   #9 (permalink)
Skittles
Super #1
 
DewKnight's Avatar
 
Joined in Aug 2004
Lives in a space ship
Hosted on dedi
6,806 posts
Gave thanks: 101
Thanked 197 times
Quote:
Originally Posted by JadedSouls View Post
I went and looked via ftp at what was on there and there was a file on there that was put on 8:23pm which was an index.html file which had that black index page on it.

I kept a copy of it, deleted it off the ftp and now my portal page is back again.
At least you still have your site!

Now I would recommend going through your site, checking any scripts you use, checking files to see if they've been modified. They got that in there somehow, and it could have been a lot worse. Try to find out how.
__________________
Mountain Dew Knight
People should not be afraid of their governments. Governments should be afraid of their people.
DewKnight is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On