Topic awaiting preservation: I got hacked! |
|
---|---|
Author | Thread |
Bipolar (III) Inmate From: f(x) |
posted 10-09-2005 22:26
Well, actuly my sisters site got hacked, but I'm the webmaster. I don't want to post any links, but I did send our host a report on the issue. |
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
posted 10-09-2005 23:56
ok, here's a basic guidline, provided the hacker only got access to your sister's account and not the whole server (likely). |
Maniac (V) Inmate From: there...no..there..... |
posted 10-10-2005 02:34
quote:
|
Bipolar (III) Inmate From: f(x) |
posted 10-10-2005 03:05
Thank TP and CP! quote: |
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
posted 10-10-2005 11:04
well, it looks like just a standard 'delete a category' request. |
Bipolar (III) Inmate From: |
posted 10-10-2005 12:57
My 2 cents... most of the time, such an intrusion is done through the forum system itself, |
Maniac (V) Mad Scientist From: :morF |
posted 10-10-2005 15:29
Easiet thing to do would be to filter the server access logs by IP address, since you have the address already (btw: I'd also suggest making sure that that's not your IP address. Check out http://www.whatismyip.com to find out if you're in the same range.) |
Bipolar (III) Inmate From: f(x) |
posted 10-11-2005 01:22
I know my IP and it's not mine. And there were multiple category deletion actions from that IP. A part of the hacking or intrusion was that all the categories exept one were deleted and a new category (containing an irc website and channel in the name) was made by the intruder. I am fairly certian that is the IP that was used for the intrusion. |
Maniac (V) Mad Scientist From: :morF |
posted 10-11-2005 01:43
Ummm... vpn.google.com doesn't exist. At all. No IP addresses registered and no domain registered. |
Maniac (V) Mad Scientist From: 100101010011 <-- right about here |
posted 10-11-2005 01:49
It exists, whois lookups will not show sub domains. |
Bipolar (III) Inmate From: f(x) |
posted 10-11-2005 01:54
It's the 4th IP down in the list in the link bitdamaged provided. And she aparently found out in http://blog.thetechgurus.net/?p=36 from a Goggle of the IP. |
Maniac (V) Mad Scientist From: :morF |
posted 10-11-2005 03:03
Aaah... silly me. Sorry about that. |
Maniac (V) Inmate From: there...no..there..... |
posted 10-11-2005 03:27
man....it's sites like that that drive me nuts! I found a site that listed exploits for every know web app known to man. complete with perl and C++ scripts. Just seems like a lot of work just to deface someones website that they more than likely took months or more to make. |
Maniac (V) Mad Scientist From: 100101010011 <-- right about here |
posted 10-11-2005 06:11
It looks like the vpn.google.com addy is for secure wireless access. I don't think that's going to tell you anything unless you track them back through google. Even then this was probably done by a wireless user over an open access point. Virtually impossible to track, maybe by MAC addy if they keep reusing the same point but I doubt anyone is going to use the resources necessary to catch this idiot. |
Bipolar (III) Inmate From: Australia |
posted 10-11-2005 07:40
Out of interest what is a good secure forum to use, my phpBB was haxxed not too long ago - no damage was done however. |
Maniac (V) Mad Scientist From: :morF |
posted 10-11-2005 09:56
MercuryBoards is good, I believe, as is Invision, but you've gotta pay for that one. Or there's the Grail, which TP will give ot anyone who asks him via email, I think. |
Paranoid (IV) Mad Scientist with Finglongers From: Germany |
posted 10-11-2005 14:36
Indeed, I do. E-Mail, icq, whatever, you'll have to ask. |
Bipolar (III) Inmate From: f(x) |
posted 10-11-2005 23:05 |