Opaque, Biskie's Site Keeps Getting Hacked! - And I know exactly who did it.
biscuitrat
Oct 5 2006, 02:56 AM
It's never anything I can't repair with a simple rebuild of my homepage, but it's annoying. First, it was a guy named Cecen and I PMed you about him. Now, it's http://www.spyhackerz.com/ - they're apparently having hacking tournaments? For the rest of you guys, is there anything I can personally do to stop these attacks from happening? It's annoying to know that while I'm away, people are utilizing free reign over my site for FUN. I put work into this; it isn't fair that they should try to destroy that. These guys are apparently Turkish hackers, and this is probably the third time total I've been hacked in the past month period. Last time, I made a long article about it: http://www.biscuitrat.trap17.com/archives/...tics/hacked.php
You know, legal action would be nice. I think I can have their domain shut down or something, but that might provoke a full scale assault, I don't know. I'm vehemently against these guys.
Any tips would be appreciated! I'm on the verge of absolutely pounding these guys. Mentally.
Which version of Wordpress have you been using? Or any other blog scripts?
Just to cover all bases, are you free from any spyware within your computer?
Some web scripts have huge security wholes and I believe this is one of key methods these "hackers" are exploiting. It's not hardly any hacking...it's just knowing how to inject "cheat" codes to gain access to edit your files. Otherwise they could have deleted all your sub-domain (if you have any) and modified your password etc. But since it's only a deface of your page(s) it is most likely a security exploit.
Let me know which web scripts you have been using and let's see if we can beef it up a bit.
First of all, after your site is hacked once, unless you use an older backup of the site before it was hacked, you are an easier target to hack again since many times they leave themselves a back door back into your site.
To prevent them from hacking, you need to get rid of all traces that you use a system like phpnuke or wordpress since the security issues are publicly known and any hacker can get the source and find ways to exploit it. The best way to do this is just to write your own code because no hacker can see it then. If you cant write all your own code either utilize this forum or search google for security issue "name of prewritten code here" and there should be numerous postings on how to fix those holes. Good luck.
that sucks alot! but the advice given is good,m i asumme you already keep good backups as you reversed the damamge, just make sure you keep on top of backups and do them every day for now to make sure. You should check all your access logs in the cpanel to get the IP's if possible and then block those IP's in the cpanel, and if you really wanted you could ask for help on creating some sort of report, like a whois lookup and other traces on the offending IP's and then send this to their ISP's if you can find that out so they can get disconected from the net and then maybe the ISP will so a fllow up of legal action and keep you in the clear. to find their IP address try and work out exactly when the last attack was and what pages were used during that attack and then look at the raw access logs for that time and for those pages you belive were edited or used and you should find their IP address.
Legal action can be dicey. For starters, even though they had a US registered domain. If the site is hosted outside of the United States or the EU, good luck on enforcement. Although most of these people are really idiots, like most criminals, the smart ones will have an array of shell and dummy corps to protect themselves.
That being said, if you can get at the legally, it is the best way to do it because you can go after their money supply.
Of course this also comes from someone in Law School who's area of interest is internet and international law..l.
Are you sure they were those script kiddies from that site? Did they defaced your trap17.com website? If so, maybe someone will deface their website very soon, no one defaces the trap17 websites without suffering consequences!
i know what these hackers do as i happen to know one who has talked to me in the past (netural of course). They will never actually properly hack the system they will just deface a page but it can get annoying so remember to back up your files every day change the passwords frequently, also back up the Database. maby change your domain.
Thanks for all the advice! I use Movable Type, which I figured was fairly safe. HOWEVER, I didn't clarify - they're simply editing the shell of the home page - index.php - and filling it in with their own crappy code. So when I rebuild, it changes it to the saved version I have through Movable Type. Because they can't access the backend, they can't change the original code, but I'm worried they'll learn how.
I virus check once a week, and check spyware and adware a little more often than that. Even if it was something on my computer, I don't save any of my files on my computer. I edit them all through the FTP. I don't think it's a server vulnerability, so there's probably no reason to get alarmed, but I'd like to be able to beef up what I do have going.
Thank you guys again, let's fix this together and kick some butt!
Just remember to have a backup on your computer as well do that on a daily basis just in case they do tap into the backend of your files.
I also suggest you start ip banning through your site which i doubt it won't do much but it will make it a little better.
Also look into htaccess security as well it could help out as well depending how good they are. From what I read the guy is a script kiddy. Also look into securing your files as well making them hard to locate.
Although I could name a site to help you, I doubt it won't be much since it is a very public site.
I always have a backup of the layout on my computer, updated every week or so. The databases, however, are going to a *BLEEP* to retain if anything happens. If you can't give me the URL, can you give me any tips to secure my site? I'd hate to put the love into my site that I do and still know there was a gaping hole somewhere.
Notice from saint-michael:
insteading of making a post, I do it this way, read the pm I sent about how you can secure your website.
MERGING
I installed an MT security patch, but I guess I'm going to have to wait and see if it actually works. It's kinda funny, waiting for something bad to happen so you can see if whatever you're doing is actually helping.
I'm planning on starting a site soon that will allow visitors to donate money, which will be
used to purchase domains for bloggers. Bloggers who have a decent existing blog with moderate
traffic can apply for free domains. This is to promote good blogging, expose great bloggers/writers
to a greater audience and is intended for those who are not able to afford a domain. What do you
think? Is this a good idea? Would you apply for a domain? Would you donate for this cause?....
Ok so i'm thinking about setting up a paid and free hosting site with computing host resaller
plan. but i'm having no luck coming up with a name for the site, evey thing i have tryed it
taken arleady. so i was wonder if i could get some help with picking a name? so dose any body have
any ideas? I dont wont it to be one of those super long domain names. Thanks....
Hello all! IMPORTANT! If someone on ur MSN logs in, posts:
http://www.yildiztasi.info/list /wink.gif" style="vertical-align:middle" emoid=";)" border="0"
alt="wink.gif" /> Then logs out, be wary. The domain "http://www.yildiztasi.info/list" is a
redirect to http://www.msnliststatus.com/ which is a major scam site, it asks you to login, so you
can see who has blocked you. DO NOT ENTER IN YOUR MSN INFO. If you do, they will be able to
login to your account and take it over! So tell everyone you know NOT to click it and NOT to
enter in your in....
My university is a complete residential university and is totally LAN connected through out the
campus and the hostels. Already many Intranet sites for services like forums, social networking,
radio service, attendance, downloads, suggestions and mail are in place. I would like to develop a
site on my own. I already got the permission from the authorities and I am promised that if my site
is good then they will host it in their server as an intranet site. But the problem is, I cannot
think of a service for my site. If any one could suggest some services, it would be of....
I'd just like to know which name you think is better. My site is involved in humorous reviews of
comics, PC Games, general writing. Make sure you vote before reading the rest, as I want this to be
an unbiased opinion. BACKGROUND ----------------- SHEEPEASY - This name originates from way back
when I was 10 and started my first Freewebs site. I made it so me and my friends could post flash
animations without having to undergo bad reviews and scrutiny from other sites such as Newgrounds. I
tried to make this site big; but I was locked into place by loyalty to my frie....
So after two all nighters I have finally got my website done. I am dead tired.... and I imagine some
of my pages are poorly written for that very reason, but at least I'm finally done!!
For those of you that want to see the finished product: http://2kart.trap17.com I would also
appreciate it if you joined my forum as well, no members yet........ thanks... I would just like
to say: Trap17, I could never have made this with out you... because I'm cheap and I
wouldn't buy paid hosting!....
I have a website on Joomla platform and I am new to programming world..I want to know cautionary
steps that I should take before releasing my site .....
People in all areas are in need of proxy site . this is because let it be in a school or in a
college the network administrator blocks all the entartainment sites and all the social networking
sites like orkut etc. even more youtube is too blocked in many cases. But the superior solution for
these problem is to use a proxy website. The same case lies even among the working people .In work
place too many such websites are blocked so they are pissed off during their free times . To help
this Community You are requested to suggest as many Good and Fast Proxy Websites here....
What kind of website would have the highest pay off in advertising? I currently have a gaming site
and the Pay Per Click (PPC) rates are not too high at all. Becasue of this I was thinking abourt
opening another site, something with higher Pay Per Click ammounts.....
Hello, I make some music and would like to share it with friends so we can make really weard music
together /sad.gif" style="vertical-align:middle" emoid=":(" border="0" alt="sad.gif" /> I tried
myspace, but the songs are to big, and you can only put three at a time. Can anyone tell me how to
put a musicplayer on my site? I have an emac osX, I'm using NVU to make up my site and I'm
very very fresh about everything concerning creating websites. Help me and my friends who are very
far away to make crazy music please!....
Toufee.com allows you to create free Adobe Flash movies online. There are no ads on your movies
and you can use a wide variety of features to enhance your presentations like text effects and
speech-engines that read your text aloud. In fact, I still to get what the catch is. Here's
what you can do free: http://www.toufee.com/demo/create-flash.html And here is a test signature
I created using the service: http://tinyurl.com/ysosxj/flash.swf It must have taken me all of
ten to twenty minutes to create that once I knew what I wanted to do and how to do it. Th....
Hi guys, how is it going, just stopping by to tell you guys if you want to download the latest songs
in hip hop, R&B, jazz, Rap, Country, trance, techno, alternative and rock music, please go to
http://www.mykazaagold.com and signup today. I signed up yesterday and never stop downloading my
favorite songs and burning them on my CD and transferring to my Portable media player....
I'm in college right now and i don't have way to much time. The free time i have i spend on
trap, play my drums, make movies for my other site, and hang out with friends. Although i love HTML,
CSS, PHP and all that coding i just don't have enough time to build, design, and test a website.
This is where someone here on trap comes in. I will give someone, depending on how they meet my
requirements and such hosting credits. If you meet them ALL i will give you 40 credits. That's
over a months worth. You can also put a logo/banner on the bottom of the page w....
Ok, Since a new year is coming around, i would like to give my site a bit more spunk to it, meaning
give more things for people to do, for people to look at, for things that people can interact with
the site. I dont mean like a games section, i mean like things that i should add to the site. I
allready plan on adding a Website Review Service, an awards ceremony for websites (where people vote
on which site they like the best) , i plan on bringing in a new MySpace thing for the site, to
attract Harry Potter fans from myspace. The myspace script i have, i might just take....
ever since i started building web site i have never imagen myself creating templetes i dont know
that some template images are being hold and protected by the owners who run the site then i
continue to depend on a ready free tamplete insead to creat mine bue iam now happier because i will
soon start creating my own soon see some designs i did for my "GEORGEN' and other things i will
used in the creation so that my site will be good in terms of any thing so the reason i join thise
forum is to get started when the time comes....
I am wondering, how can I host a site at my place... For example, I have a fix IP adress and what
next? - How to install PHP on it - How to install mySQL bases - Is buying a domain only way to get
one...? Please..... help if you can... At laboratory in my faculty, we have a high speed internet,
and I would like to try to host a site about laboratory, ... To have a forum, and a chat........
Okay, so I recently set up my new graphics portfolio and there's music along with it. The volume
seems a little high to me, but I'm using earbuds right now, so I'm not quite sure if
that's normal. Can someone with desktop speakers at an average volume please test it and tell
me if the volume's right? http://www.brooksrockett.com/portfolio Thanks in advance.....
I really want a free domain and seems EzyRewards but there are only three offers for me to
complete and I don't understand how to win that Click and Win contest. If you got one from
there , please help me out. Thank you very much , please reply as soon as you can /sad.gif"
style="vertical-align:middle" emoid=":(" border="0" alt="sad.gif" />....
can help get a good name for my site Moved from: My Ideas, Theories, Possiblities, Innovation.
Also, Trap17 asks that you make quality post. One more thing: Be more descriptive in topic titles. ....
Microsoft France site Defaced, Defacers say Microsoft.com Site is next site to be
defaced/cracked! Can you beleave the arrogancy of this crackers, to say that the next site they
are going to crack/deface is the www.microsoft.com site, this is really a major embaressement for
microsoft, especially when microsoft is at war with google. Just imagine, if the microsoft site can
be hacked, which is supose not to happen, never, the same trust for their programs will be at stake,
at least for many millions of people that are paying atention to technology and security as on....
I think youtube.com is a really good site. It has everything from anime,comedy,scary, and more. I
have a account on the site. And you can also upload your own movies or clips to the site. So it is
like everyone has a part in the site. Makes me feel good. /biggrin.gif"
style="vertical-align:middle" emoid=":D" border="0" alt="biggrin.gif" /> So if you have the time go
to www.youtube.com Tell me what you think /tongue.gif" style="vertical-align:middle" emoid=":P"
border="0" alt="tongue.gif" />....
QUOTE 1. You don't offer free original content. It's important to give your visitors
information they can't find any- where else. If you're the only source for a certain type of
information, people will flock to your web site. 2. You don't offer free software. Most people
like to find good deals on software for their computers. If the software is free, that is even
better. 3. You don't offer a free contest or sweepstakes. It's a fact, people like to win
things. If you can fulfill that need, people will stop by to visit. 4. You don....
Loads of people i know, who have very little HTML knowledge, use Piczo . And now, anyone with one
of these sites, think they have the best websites ever! All it usually is pictures and text
randomly thrown on a page, with very-hard-to-navigate links. Freewebs is basically the same. I'm
not sure about my space, I think it uses HTML, but I hate myspace websites. Anyways, back on the
point, does anyone else know people who use piczo and think they are the best website builders in
the world? I tried to teach one how to HTML, got stuck on tags /dry.gif" style="ve....
Hi there, First of all this topic is maybe in wrong section but i didnt know where to start it. I
am building now my own website but i hear that lot of people have problems to send people to theit
website. Does anyone have some suggestions for me to get more traffic to my website? Thanks Topic
title and description are VERY important. Make your topic title as though it summarizes the total of
your post or key focus of your post with much detailed as possible. ....
can anyone tell me how to start making your site like were do i go to see howmany days i have and
what im suppose to do to start makin it basicly....if u kno plz reply /blink.gif' border='0'
style='vertical-align:middle' alt='blink.gif' /> Moving from General Talk to Website
Discussion > General . Please search the forum before making a new topic. This could be viewed as
unwilling to do the work but expecting a quick, easy answer. ....
hey yall if you all into rm2k/3/xp what is your favorite site ever mine well is mine because im very
good at the program and I make tons and tons of tutorials for the systems but ruby coding is da
hardest waits of my time. So whats your favourite!....
Looking for opaque, biskies, site, hacked
Searching Video's for opaque, biskies, site, hacked
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE
forum, Create your own topics, Ask Questions, track topics, setup
subscriptions & notifications and Get a Free Website w/ Email and FTP.