icon Learn how to get the most out of Surmunity - read our forum tips here! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Choosing Surpass » Signed Up? » Help! webserver being hacked!

Signed Up? If you're new with a question, ask here!

Reply
 
LinkBack Thread Tools Search this Thread
Old September 1st, 2006, 10:29 AM   #10 (permalink)
minor deity
Super #1
 
Bigjohn's Avatar
 
Joined in Apr 2004
Lives in Georgia
Hosted on XEON
7,229 posts
Gave thanks: 19
Thanked 91 times
why do they spend all their effort defacing and hacking? They should be writing awesome applications instead...
__________________
Proud to be a Surmunity Mod!
XEON PASS60 PASS61
Make a fundamental difference!
My Sites:
Curious about Brewing Beer? Join the community!
>>>>> Some Change is GOOD! Keep your paycheck! Support the Fair Tax
Get into an Art museum
Victorian London
It's your brain -ON WEB - mybrainhost.com (under development)
What SHOULD Government do? Much Less than it Does!
Bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 11:33 AM   #11 (permalink)
Registered User
Comfy Contributor
 
schupp's Avatar
 
Joined in Oct 2004
Lives in Reykjavík/Toronto
Hosted on Pass16/18
168 posts
Gave thanks: 0
Thanked 0 times
Quote:
Originally Posted by Bigjohn View Post
why do they spend all their effort defacing and hacking? They should be writing awesome applications instead...
I've always wondered the same, what is the joy in vandalism?
However I don't think it is about that so much anymore. The trend is now that the more talented hackers (not the immature script kiddy bums) are being *paid* by spammers, thiefs, and terrorists to write hacks for their needs.

Grab your raw logs and have a look. If you don't see hack attempts I'd be very surprised. Back track some of them and you'll bump into some very unsavoury people. I've seen a few that could very well have been serious terror groups.

It is up to all the site owners to keep their sites secure. I wish people cared but too many don't, they just want that blingy piece of crap on their site no matter what it does to everyone else. It only takes one per server and no doubt that number is much higher.
__________________
Pass16
Pass39
schupp is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 11:38 AM   #12 (permalink)
minor deity
Super #1
 
Bigjohn's Avatar
 
Joined in Apr 2004
Lives in Georgia
Hosted on XEON
7,229 posts
Gave thanks: 19
Thanked 91 times
I'm just about ready to block any domain that comes from russia or china...
__________________
Proud to be a Surmunity Mod!
XEON PASS60 PASS61
Make a fundamental difference!
My Sites:
Curious about Brewing Beer? Join the community!
>>>>> Some Change is GOOD! Keep your paycheck! Support the Fair Tax
Get into an Art museum
Victorian London
It's your brain -ON WEB - mybrainhost.com (under development)
What SHOULD Government do? Much Less than it Does!
Bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 11:48 AM   #13 (permalink)
Registered User
Comfy Contributor
 
schupp's Avatar
 
Joined in Oct 2004
Lives in Reykjavík/Toronto
Hosted on Pass16/18
168 posts
Gave thanks: 0
Thanked 0 times
I'm way ahead of ya.
My list of IP blocks slowly gets longer and longer....

Too bad that doesn't help when a neighbour site gets nailed and the script walks the server.

Look around, there is a massive crack campaign going on everywhere right now. I had a client in NYC that doesn't use Surpass but is having big trouble with routing caused by these attacks.
__________________
Pass16
Pass39
schupp is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 12:05 PM   #14 (permalink)
Insanely
Super #1
 
Skipdawg's Avatar
 
Joined in Jul 2005
Lives in Northwest USA
4,154 posts
Gave thanks: 39
Thanked 78 times
Quote:
Originally Posted by Bigjohn View Post
I'm just about ready to block any domain that comes from russia or china...
I've already done that. Got tired of all the spam and always seeing searches for exploits in the error log. So I just shut down all from .cn and .ru
__________________
Skipdawg is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 12:08 PM   #15 (permalink)
Race Surpass
Super #1
 
MarkRH's Avatar
 
Joined in Jul 2006
Lives in Oklahoma City, OK
Hosted on sh102
1,176 posts
Gave thanks: 18
Thanked 85 times
I get at least 100 attempts a day to add crap into my Guestbook. I also get a number of attempts that show up in my error log to access non-existant guestbook pages and scripts. Most of these, I imagine, are attempts to add links to their or their client's websites to improve search page ranking in which part of the page ranking algorithm is based on how many other pages link back to it. I've noticed a few of these attempts have been from other webhost companies.

I remember one day about a year or two (time flies) ago, I came home to discover 55 ads in my guestbook for Online Casino Sites. This was before I added all the protections I have now.

Stupid bots, hackers..
MarkRH is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 12:15 PM   #16 (permalink)
minor deity
Super #1
 
Bigjohn's Avatar
 
Joined in Apr 2004
Lives in Georgia
Hosted on XEON
7,229 posts
Gave thanks: 19
Thanked 91 times
what protections do you have, Mark?
__________________
Proud to be a Surmunity Mod!
XEON PASS60 PASS61
Make a fundamental difference!
My Sites:
Curious about Brewing Beer? Join the community!
>>>>> Some Change is GOOD! Keep your paycheck! Support the Fair Tax
Get into an Art museum
Victorian London
It's your brain -ON WEB - mybrainhost.com (under development)
What SHOULD Government do? Much Less than it Does!
Bigjohn is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 12:37 PM   #17 (permalink)
Race Surpass
Super #1
 
MarkRH's Avatar
 
Joined in Jul 2006
Lives in Oklahoma City, OK
Hosted on sh102
1,176 posts
Gave thanks: 18
Thanked 85 times
I had been using the ever popular Matt Wright's Perl Guestbook script that has been around for many years. I re-wrote a new one from scratch using PHP.. doing that alone has prevented all the attempts at running /cgi-bin/guestbook.pl as that no longer exists on my site.

The main thing I do now is generate a random 5 character gif image everytime the add entry page is loaded that the user has to enter into the form and must of course match. The correct random value is stored in a SESSION variable which gets passed to the form handling script. I also use a hidden field that contains the field names of the items that must be completed.

About 99 percent of the attempts fail because the SESSION variable itself does not exist (which tells me that it did not even call the script that generates the image) and about 1% are blocked because the hidden field name does not exist, which tells me they weren't even using my form.

I should save what they were trying to add in some file somewhere hmmm..
MarkRH is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old September 1st, 2006, 1:12 PM   #18 (permalink)
DemonicAngel
Super #1
 
twirp's Avatar
 
Joined in Aug 2004
Lives in Wherever The World Takes Me
Hosted on Pass76
1,769 posts
Gave thanks: 24
Thanked 32 times
Quote:
Originally Posted by Skipdawg View Post
Awesome! It's just amazing what all hackers can do some times.
if you allow .rar, .zip, .tar, or basically any archive to be uploaded to your site, someone can upload malicious php code.
i.e. bleh.php.zip or bleh.php.rar (these files have nothing bad, just ask for a name, and then they say hello).
but as you can see the extension is .php.zip if it were changed to just .zip, the code won't execute.
so it's best to rename the file that is being uploaded, and posibly scan the file for coding...
__________________
You wear Vans so high school kids will think that you can skate. He wears Vans because he can skate. TwiRp wears Vans because they were on sale. Pass76 wants Vans.
twirp is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On