Web Host was attacked by a hacker
64|
|
LADIES HACKING JACKET GREY WITH PIN STRIP SIZE 10-12
Current Bid: $26.10
|
|
|
Happy Hacking Keyboard Professional 2 HHKB Pro2
Current Bid: $298.00
|
|
|
Backtrack Linux 3 & 4 Security Testing & Learn Hacking
Current Bid: $2.99
|
|
|
SUPER VTG LAMBOURNE DERBY TWEED HACKING JACKET 44
Current Bid: $93.84
|
|
|
Xbox 360 Flashing,Modding,and Hacking Guide
Current Bid: $.99
|
|
|
HACKING SECRETS REVEALED HACKERS GUIDE SECURITY HACK CD
Current Bid: $9.95
|
I have just started using CARP and .php websites which I uploaded to my web host and after two weeks my hosting account was attacked by a hacker through an insecure .php script. I'm not sure which is to blame as they both contain .php scripts. I had to delete the whole domain just to make sure I had removed all of the scripts deployed by the hacker. I have removed CARP from my web host also as I'm not really sure how to secure it so it can't happen again so if any one could help I would be grateful. The chmod permissions I set were those given on the install instructions.
The hacker used my hosting account to spam mail from for about 10 hours before my hosting provider informed me of spam complaints. I checked through my web space explorer and found all the index pages in one domain had been changed to the hackers page with a picture of some guy, Russian music playing and a message saying;
"Hacked crazy_fb & imparator"
"Nush ile Uslanmayani Etmeli Tekdir, Tekdir ile Uslanmayanin Hakki Hack'dir."
"I'm Coding My Love On Websites"
The scripts below were placed in some of me folders to send the spam mail;
/files/ekwe.php
/files/carprss.php
/files/cool.php
Ok, he hacked my domain to use as a mail server but there was no need to re-write my index pages was there!! There were other successful exploits found in other folders;
Script Variable
/files/carprss.php $CarpPath
/files/carprss.php $full_path_to_public_program,CarpPath
/files/redirect.php $file
/files/carprss.php $CarpPath
/files/redirect.php $file
/files/journal.php $m
/journal.php $m
Not even sure what they mean as I am quite new to .php websites and not really sure if it safe to upload the websites again which are on my hard drive on my PC. Other domains had HTML websites on and were not touched by the hacker. I did question the security of my web hosting provider, but yeah, it was my fault for uploading insecure .php scripts. But as I'm new to .php how do I know which ones are secure and which ones aren't?
|
|
LADIES HACKING JACKET GREY WITH PIN STRIP SIZE 10-12
Current Bid: $26.10
|
|
|
Happy Hacking Keyboard Professional 2 HHKB Pro2
Current Bid: $298.00
|
|
|
Backtrack Linux 3 & 4 Security Testing & Learn Hacking
Current Bid: $2.99
|
|
|
SUPER VTG LAMBOURNE DERBY TWEED HACKING JACKET 44
Current Bid: $93.84
|
|
|
Xbox 360 Flashing,Modding,and Hacking Guide
Current Bid: $.99
|
|
|
HACKING SECRETS REVEALED HACKERS GUIDE SECURITY HACK CD
Current Bid: $9.95
|
|
Hackers
Price: $8.42
List Price: $14.98 |
|
A Writer's Reference with 2009 MLA Update
Price: $45.00
|
|
|
Hackers Are People Too
Price: $10.00
List Price: $13.37 |
|
Hackers - Wizards of the Electronic Age
Price: $14.95
List Price: $14.95 |
|
Writer's Reference 6e & MLA Quick Reference Card
Price: $65.00
|
|
Track Down
Price: $5.92
List Price: $14.99 |
|
Hacking: The Art of Exploitation, 2nd Edition
Price: $29.99
List Price: $49.95 |
|
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Price: $28.63
List Price: $50.00 |
PrintShare it! — Rate it: up down flag this hub









