PDA

View Full Version : Help! My website's been hacked!


xtro
08/23/2006, 12:55
xtro32.com (http://xtro32.com)

Someone's hacked my site. What do I do?!!

justin
08/23/2006, 14:24
Is that for real? Who is your web hosting provider?

magicnetwork
08/23/2006, 15:06
xtro32.com (http://xtro32.com)

Someone's hacked my site. What do I do?!!

Maybe restore your website from backup? :)

Then remove any third-party scripts and check your website for security holes.

contrid
08/23/2006, 15:15
Sorry to hear about that man. I'm sure your host can help you with that issue.

trendywebs
08/23/2006, 18:40
Hello, is the domain lost or the server just got compromised? If your domain is gone then i'm afraid nothing can be done. But, if its your server only then ask the admin to restore it back to the last backup they had taken. And make sure you kick their ass for the lapse of security if it happened at their end! My website got hacked a year ago by some script kiddie who had some exploit of globat.com and globat had to refund all my hosting fees because of the charges i had pressed on them for the very same issue. It's very much possible that you can get a leverage on your hosting company. Let me know if something i can help you with. Coz i've had plenty of the same kind of bad experiences before.

Regards,

Anirban.

RichardJohn
08/23/2006, 19:31
That's the best design of a defacement page I've seen :eek:

I had a defacement the other week that came from an old (unused) version of wordpress.
It overwrote index.php with
"**** YOU AMERICA! **** YOU ISRAEL! TAKE YOUR WAR MACHINES AND GO HOME YOU IMPERIALIST DOGS!"

I just restored the last backup, and uninstalled Wordpress to stop it happening again.

Sixfire
08/24/2006, 00:53
Hi! I was wondering why not hack the sites that hacked us!

But is the name/website of the hacker posted in Xtro's website true? Or is it placed there by someone else who wants to get even with them?

contrid
08/24/2006, 01:03
Hi! I was wondering why not hack the sites that hacked us!

But is the name/website of the hacker posted in Xtro's website true? Or is it placed there by someone else who wants to get even with them?

I don't think it will be the real hacker's site. Not sure...
I'm quite sick of hackers these days. I'm doing constant development on a site for a client, and he keeps on receiving threads that they are going to take over his site. Atleast I know everything is secure. ;)

This site I'm talking about is a dedicated server, so we have full control over what goes on...but sometimes with shared hosting, the hosting company doesn't ensure that all ports are secured, and that's the main reason why sites get hacked. ( I think... )

xtro
08/24/2006, 02:55
Wow, what a response! Thanks to everyone. I got in touch with the hosting company (honesting.com!), they've been having the exact same shite, so all I have to do is tell them to restore it.

But now I have this need for revenge...

contrid
08/24/2006, 09:30
I can just imagine how confused/furious you are right now.
Who know...if you do some research...or hire a russian hacking team, you might be able to take revenge against these guys. ;)

trendywebs
08/24/2006, 09:57
Wow, what a response! Thanks to everyone. I got in touch with the hosting company (honesting.com!), they've been having the exact same shite, so all I have to do is tell them to restore it.

But now I have this need for revenge...

Go bro go:D kick their ass! But, before you do that...make sure you secure your server very tight. Check for any open shell's thats one of the major backdoors for these jerks to creep into the sites. I forgot what it was exactly but there's a way to write an index.htm on the server root with some kind of POST action. Tried that with geocities and .tk domains long time back. Also if possible get someone to check your server's security...another hacker will be the best option as they have all the ideas about the latest exploits etc. Get your site up again and kick their ass:P. You said that your hosting has the same problem all over then maybe its some sort of root access on the shared hosting that the hackers got access to.

Regards,

Anirban.:)

xtro
08/24/2006, 10:29
Luckily it was only the index.htm that got hacked, all the other stuff is still there, so that's a relief. It's also a relief to know that it wasn't a personal attack.

Thanks again to everyone :)

justin
08/26/2006, 09:19
So when are you going to update your site, it's still in its hacked form.

xtro
08/28/2006, 04:21
Yeah I know. I'm waiting for the hosting company to get their finger out.

blom
08/29/2006, 02:24
Luckily it was only the index.htm that got hacked, all the other stuff is still there, so that's a relief.

Well, that means they're good people and most likely (ab)used some script you use on that server (guestbook, contact form etc). If they can write to arbitrary files, they could probably also include a `rm -fr ~/` command, which they didn't. Good people ;-)

xtro
08/29/2006, 02:44
They'd be even better people if they just didn't fucking do it.

If you want to spread a message and show you've got balls, hack the F.B.I.

savire
08/29/2006, 06:28
They'd be even better people if they just didn't fucking do it.

If you want to spread a message and show you've got balls, hack the F.B.I.

Yeah agree with you. Strong MAN must fight with a strong opponents. That act just a coward. No harsh intention but that's a hero must do :cool:

trendywebs
09/04/2006, 16:08
Its still hacked!! How come you're not taking down that page? Or did they do it again?

xtro
09/05/2006, 03:21
No, I'm waiting for the hosting company to pull their finger out. To tell you the truth I'm growing quite fond of it, actually!

contrid
09/05/2006, 10:43
No, I'm waiting for the hosting company to pull their finger out. To tell you the truth I'm growing quite fond of it, actually!

Maybe you should remind your host.
Don't you have ftp access to reupload your site?

xtro
09/06/2006, 05:09
Sorted!

I feel quite proud of myself now.