Web Host was attacked by a hacker
66|
|
The Unofficial Guide to Ethical Hacking by Ankit Fadia
Current Bid: $.99
|
|
|
Happy Hacking Keyboard Professional 2 HHKB Pro2
Current Bid: $288.00
|
|
|
VERY VTG HTOOTH CHECK HARRIS TWEED HACKING JACKET 40 L
Current Bid: $66.04
|
|
|
Vtg Abercrombie Fitch Norman Hilton Hacking Jacket 44XL
Current Bid: $79.95
|
|
|
Mint J CREW Wool Tweed HACKING Jacket Blazer Beige 2 XS
Current Bid: $24.95
|
|
|
EC-Council – Ethical Hacking and Countermeasures LAB
Current Bid: $40.00
|
I have just started using CARP and .php websites which I uploaded to my web host and after two weeks my hosting account was attacked by a hacker through an insecure .php script. I'm not sure which is to blame as they both contain .php scripts. I had to delete the whole domain just to make sure I had removed all of the scripts deployed by the hacker. I have removed CARP from my web host also as I'm not really sure how to secure it so it can't happen again so if any one could help I would be grateful. The chmod permissions I set were those given on the install instructions.
The hacker used my hosting account to spam mail from for about 10 hours before my hosting provider informed me of spam complaints. I checked through my web space explorer and found all the index pages in one domain had been changed to the hackers page with a picture of some guy, Russian music playing and a message saying;
"Hacked crazy_fb & imparator"
"Nush ile Uslanmayani Etmeli Tekdir, Tekdir ile Uslanmayanin Hakki Hack'dir."
"I'm Coding My Love On Websites"
The scripts below were placed in some of me folders to send the spam mail;
/files/ekwe.php
/files/carprss.php
/files/cool.php
Ok, he hacked my domain to use as a mail server but there was no need to re-write my index pages was there!! There were other successful exploits found in other folders;
Script Variable
/files/carprss.php $CarpPath
/files/carprss.php $full_path_to_public_program,CarpPath
/files/redirect.php $file
/files/carprss.php $CarpPath
/files/redirect.php $file
/files/journal.php $m
/journal.php $m
Not even sure what they mean as I am quite new to .php websites and not really sure if it safe to upload the websites again which are on my hard drive on my PC. Other domains had HTML websites on and were not touched by the hacker. I did question the security of my web hosting provider, but yeah, it was my fault for uploading insecure .php scripts. But as I'm new to .php how do I know which ones are secure and which ones aren't?
|
|
The Unofficial Guide to Ethical Hacking by Ankit Fadia
Current Bid: $.99
|
|
|
Happy Hacking Keyboard Professional 2 HHKB Pro2
Current Bid: $288.00
|
|
|
VERY VTG HTOOTH CHECK HARRIS TWEED HACKING JACKET 40 L
Current Bid: $66.04
|
|
|
Vtg Abercrombie Fitch Norman Hilton Hacking Jacket 44XL
Current Bid: $79.95
|
|
|
Mint J CREW Wool Tweed HACKING Jacket Blazer Beige 2 XS
Current Bid: $24.95
|
|
|
EC-Council – Ethical Hacking and Countermeasures LAB
Current Bid: $40.00
|
|
Hackers
Price: $4.80
List Price: $14.98 |
|
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Price: $27.38
List Price: $50.00 |
|
|
Hackers Are People Too
Price: $10.00
List Price: $13.37 |
|
|
A Pocket Style Manual 5e with 2009 MLA Update
Price: $18.98
|
|
Hackers - Wizards of the Electronic Age
Price: $14.95
List Price: $14.95 |
|
Writer's Reference 6e & MLA Quick Reference Card
Price: $65.00
|
|
|
Hacker's Delight
Price: $35.47
List Price: $54.99 |
|
Two
Price: $12.04
List Price: $16.98 |
PrintShare it! — Rate it: up down flag this hub









