Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Opaque, Biskie's Site Keeps Getting Hacked!, And I know exactly who did it.
Rating 5 V
biscuitrat
post Oct 5 2006, 02:56 AM
Post #1


Kween of Everything :)
***********

Group: Members
Posts: 1,052
Joined: 16-October 04
From: Houston, Tejas :D
Member No.: 1,774



It's never anything I can't repair with a simple rebuild of my homepage, but it's annoying. First, it was a guy named Cecen and I PMed you about him. Now, it's http://www.spyhackerz.com/ - they're apparently having hacking tournaments? For the rest of you guys, is there anything I can personally do to stop these attacks from happening? It's annoying to know that while I'm away, people are utilizing free reign over my site for FUN. I put work into this; it isn't fair that they should try to destroy that. These guys are apparently Turkish hackers, and this is probably the third time total I've been hacked in the past month period. Last time, I made a long article about it: http://www.biscuitrat.trap17.com/archives/...tics/hacked.php

You know, legal action would be nice. I think I can have their domain shut down or something, but that might provoke a full scale assault, I don't know. I'm vehemently against these guys.

Any tips would be appreciated! I'm on the verge of absolutely pounding these guys. Mentally.
Go to the top of the page
 
+Quote Post
BuffaloHELP
post Oct 5 2006, 05:13 AM
Post #2


Desperately seeking "any key" to continue...
Group Icon

Group: Admin
Posts: 3,497
Joined: 23-April 05
From: Trap17 storage box
Member No.: 6,042



Which version of Wordpress have you been using? Or any other blog scripts?

Just to cover all bases, are you free from any spyware within your computer?

Some web scripts have huge security wholes and I believe this is one of key methods these "hackers" are exploiting. It's not hardly any hacking...it's just knowing how to inject "cheat" codes to gain access to edit your files. Otherwise they could have deleted all your sub-domain (if you have any) and modified your password etc. But since it's only a deface of your page(s) it is most likely a security exploit.

Let me know which web scripts you have been using and let's see if we can beef it up a bit.
Go to the top of the page
 
+Quote Post
fffanatics
post Oct 5 2006, 02:24 PM
Post #3


Privileged Member
*********

Group: [HOSTED]
Posts: 936
Joined: 14-April 05
From: West Chester, PA
Member No.: 5,636



First of all, after your site is hacked once, unless you use an older backup of the site before it was hacked, you are an easier target to hack again since many times they leave themselves a back door back into your site.

To prevent them from hacking, you need to get rid of all traces that you use a system like phpnuke or wordpress since the security issues are publicly known and any hacker can get the source and find ways to exploit it. The best way to do this is just to write your own code because no hacker can see it then. If you cant write all your own code either utilize this forum or search google for security issue "name of prewritten code here" and there should be numerous postings on how to fix those holes. Good luck.
Go to the top of the page
 
+Quote Post
shadowx
post Oct 5 2006, 03:13 PM
Post #4


A clever man learns from his own mistakes, a WISE man learns from those of OTHERS
***********

Group: [HOSTED]
Posts: 1,028
Joined: 12-April 06
From: Essex, UK
Member No.: 21,719



that sucks alot! but the advice given is good,m i asumme you already keep good backups as you reversed the damamge, just make sure you keep on top of backups and do them every day for now to make sure. You should check all your access logs in the cpanel to get the IP's if possible and then block those IP's in the cpanel, and if you really wanted you could ask for help on creating some sort of report, like a whois lookup and other traces on the offending IP's and then send this to their ISP's if you can find that out so they can get disconected from the net and then maybe the ISP will so a fllow up of legal action and keep you in the clear. to find their IP address try and work out exactly when the last attack was and what pages were used during that attack and then look at the raw access logs for that time and for those pages you belive were edited or used and you should find their IP address.

Go to the top of the page
 
+Quote Post
blendergalactica
post Oct 5 2006, 05:47 PM
Post #5


Member [Level 3]
******

Group: Members
Posts: 95
Joined: 4-October 06
Member No.: 31,075



Legal action can be dicey. For starters, even though they had a US registered domain. If the site is hosted outside of the United States or the EU, good luck on enforcement. Although most of these people are really idiots, like most criminals, the smart ones will have an array of shell and dummy corps to protect themselves.

That being said, if you can get at the legally, it is the best way to do it because you can go after their money supply.

Of course this also comes from someone in Law School who's area of interest is internet and international law..l.
Go to the top of the page
 
+Quote Post
Lyon2
post Oct 5 2006, 07:24 PM
Post #6


The Ethical Hacker
***********

Group: [HOSTED]
Posts: 1,171
Joined: 27-May 05
From: Portugal (Europe)
Member No.: 7,566



Are you sure they were those script kiddies from that site?
Did they defaced your trap17.com website?
If so, maybe someone will deface their website very soon, no one defaces the trap17 websites without suffering consequences!
Go to the top of the page
 
+Quote Post
CrazyRob
post Oct 5 2006, 08:25 PM
Post #7


ITS ALIVE.....MUHHHAAAA
*********

Group: Members
Posts: 531
Joined: 17-October 05
From: Chippenham UK
Member No.: 13,031



i know what these hackers do as i happen to know one who has talked to me in the past (netural of course).
They will never actually properly hack the system they will just deface a page but it can get annoying so remember to back up your files every day change the passwords frequently, also back up the Database. maby change your domain.
Go to the top of the page
 
+Quote Post
biscuitrat
post Oct 5 2006, 08:53 PM
Post #8


Kween of Everything :)
***********

Group: Members
Posts: 1,052
Joined: 16-October 04
From: Houston, Tejas :D
Member No.: 1,774



Thanks for all the advice! I use Movable Type, which I figured was fairly safe. HOWEVER, I didn't clarify - they're simply editing the shell of the home page - index.php - and filling it in with their own crappy code. So when I rebuild, it changes it to the saved version I have through Movable Type. Because they can't access the backend, they can't change the original code, but I'm worried they'll learn how.

I virus check once a week, and check spyware and adware a little more often than that. Even if it was something on my computer, I don't save any of my files on my computer. I edit them all through the FTP. I don't think it's a server vulnerability, so there's probably no reason to get alarmed, but I'd like to be able to beef up what I do have going.

Thank you guys again, let's fix this together and kick some butt!

<3 Biskie
Go to the top of the page
 
+Quote Post
Saint_Michael
post Oct 7 2006, 02:43 AM
Post #9


$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3
*********************

Group: [HOSTED]
Posts: 6,563
Joined: 21-September 04
From: 9r33|\| 399$ 4|\|D 5P4/\/\
Member No.: 1,218
T17 GFX Crew



Just remember to have a backup on your computer as well do that on a daily basis just in case they do tap into the backend of your files.

I also suggest you start ip banning through your site which i doubt it won't do much but it will make it a little better.

Also look into htaccess security as well it could help out as well depending how good they are. From what I read the guy is a script kiddy. Also look into securing your files as well making them hard to locate.

Although I could name a site to help you, I doubt it won't be much since it is a very public site.