• Twitter
  • Facebook
  • Blog
  • Blogs
  • FAQ

Go Back   Talk Tennis > Miscellaneous > Odds & Ends
Reload this Page Help, somebody hack my website...
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Display Modes
Old 01-24-2011, 04:07 AM   #1
jmverdugo
Hall Of Fame
 
jmverdugo's Avatar
 
Join Date: Nov 2006
Location: Houston, TX
Posts: 2,965
Default Help, somebody hack my website...

Here is the thing, I work for a small company and I am (among other things) in charge of our websites, I made them, really simple stuff as I am definitelly not an expert. The first week of January we got a warning that a huge amount of emails were sent from our domain. We were told by our host that there is a script causing problems, which is strange because - as far as I know - there are no scripts on our websites. Today I am checking all the files and see on the main folder a couple of PHP file that were not there before and I definitelly did not upload them, I do not even know what they are, the names are 1.php and css.include.php. Any idea if this could be the problem? How did they hack our website?

Thank you very much in advance for all the help you can provide.

JM.
jmverdugo is offline   Reply With Quote
jmverdugo
View Public Profile
Find More Posts by jmverdugo
Old 01-24-2011, 06:38 AM   #2
jigar
Professional
 
jigar's Avatar
 
Join Date: Sep 2006
Location: NV, USA
Posts: 1,185
Default

first of all change all your web hosting password.
Reset passwords for FTP, database and email.
Call web hosting company and ask them to restart your virtual machine.
Delete all the accounts either you don't need or created including ftp, emails, database users and many other your have.

this forum might not be the best place to look for help.
jigar is offline   Reply With Quote
jigar
View Public Profile
Find More Posts by jigar
Old 01-24-2011, 07:44 AM   #3
JoelDali
Legend
 
JoelDali's Avatar
 
Join Date: Mar 2009
Posts: 9,013
Default

I could send email "from your domain" all day.

Get the headers of one of the emails, look at the originating IP.

Is it your virtual IP that the emails were physically sent from?

If yes, is anonymous relaying enabled on the server?

Just because 1000 emails end in my box from troll-master-tennis.com doesn't mean that they really came from troll-master-tennis.com.

Post the code from these files.

Who is your web hosting provider?

If they are worth anything, they should be able to tell you more about the issue than yourself or a mastermind high paid hacking genius such as myself or Tina, or even Tina's pet rabbit.
__________________
There he goes. One of God's own prototypes. A mutant of some kind never even considered for mass production. Too weird to live and too rare to die.
JoelDali is offline   Reply With Quote
JoelDali
View Public Profile
Find More Posts by JoelDali
Old 01-24-2011, 07:48 AM   #4
SFrazeur
Legend
 
SFrazeur's Avatar
 
Join Date: Mar 2006
Location: 1164 Morning Glory Circle
Posts: 5,703
Default

Tina's pet rabbit IS a mastermind! Turned an old washing machine I had into an iPhone.

-SF
__________________
Babolat Pure Drive "Black" (1/4) w/ Skin Feel replacment grip.
Solinco Tour Bite 16 @ 55 and Tourna Grip XL
SFrazeur is offline   Reply With Quote
SFrazeur
View Public Profile
Find More Posts by SFrazeur
Old 01-24-2011, 10:00 AM   #5
Wakenslam
Rookie
 
Wakenslam's Avatar
 
Join Date: Jul 2009
Location: ATL
Posts: 200
Default

Next time don't use "password" as your password.
Wakenslam is offline   Reply With Quote
Wakenslam
View Public Profile
Find More Posts by Wakenslam
Old 01-26-2011, 12:00 AM   #6
Eph
Professional
 
Eph's Avatar
 
Join Date: Oct 2007
Location: Cambridge, MA
Posts: 850
Default

What applications are you running? Are you using a shared host (I assume so)? Linux or Windows?

More information, the better.

Don't use ftp. Use sftp.

Update any software that has security holes ASAP (don't forget backups).

Setup at least two backup methods (time interval depends on if your site is static or dynamic, if the latter, how often content changes). Rsync is good and I use Amazon Web Services to keep off-site backups (encrypted, of course), and a copy goes to my home server.

Use secure passwords (something different for each password). Keep passwords in a master file. Do not email passwords to one another in plaintext.

Don't postit passwords to your monitor.

Type 'pwgen -sny 18' in a shell to retrieve good security passwords. If you can't install pwgen, look around online for something that works on your OS.

Pay someone to scan your directories and remove malicious code.

Check logs (if you have access). /var/log in most *nix setups (check READMEs in window's setups).

Disable root login. Use sudo.

Setup proper ACLs.


Read this: http://library.linode.com/security/basics/


Hope that helps.
__________________
By all means marry. If you get a good wife, you'll be happy. If you get a bad one, you'll become a philosopher. - Socrates
Eph is offline   Reply With Quote
Eph
View Public Profile
Find More Posts by Eph
Old 01-26-2011, 03:37 AM   #7
albino smurf
Professional
 
albino smurf's Avatar
 
Join Date: Mar 2008
Location: In a cloud of yellow fuzz
Posts: 961
Default

^^^nice link and good advice from eph.
__________________
Dude, where's my post?
albino smurf is offline   Reply With Quote
albino smurf
View Public Profile
Find More Posts by albino smurf
Old 01-26-2011, 04:09 AM   #8
Dave M
Hall Of Fame
 
Join Date: Mar 2007
Location: England
Posts: 1,865
Default

Quote:
Originally Posted by Wakenslam View Post
Next time don't use "password" as your password.
i've always foud "letmein" to be much safer.
Oh no,now you know.................
Dave M is offline   Reply With Quote
Dave M
View Public Profile
Find More Posts by Dave M
Old 01-26-2011, 04:53 AM   #9
jmverdugo
Hall Of Fame
 
jmverdugo's Avatar
 
Join Date: Nov 2006
Location: Houston, TX
Posts: 2,965
Default

Thank you all for your help, it seems like we solve the problem. But yes we will follow most of the advice here to stop this to happen again. I funny thing happened yesterday though, I notice the site running slow and our email account not working so I panic thinking that everything was happening again and contacted the hosting provider, their answer was:

"The server is currently under a DDOS attack. Our admins are currently working to block the attackers and clean out the server. "

Boy I do not know what this is but for sure sounds like trouble, it sounds like a line of Tron or another movie, War in the IT room or something like it...
jmverdugo is offline   Reply With Quote
jmverdugo
View Public Profile
Find More Posts by jmverdugo
Old 01-26-2011, 01:38 PM   #10
GetBetterer
Hall Of Fame
 
GetBetterer's Avatar
 
Join Date: Apr 2010
Location: Mesa, AZ
Posts: 1,648
Default

A DDoS attack can be done from any computer.

It's basically when one computer sends out various ping signals to a website. Most websites and servers can efficient block DDoSing (your famous websites like Google, Microsoft.com, etc., or they can handle several signals at once).

Putting it in Tron form, imagine there are a bunch of programs going into Mastermind at once, and he's all like "ARRRRRRRGGGGGGGGGGGG TOO MANY PROGRAMS!" and then he shuts down. Some websites can't handle the traffic (YouTube obviously handle LOTS of traffic).
__________________
"You have to expect things of yourself before you can do them." -Michael Jordan
http://tt.tennis-warehouse.com/showthread.php?t=354979
GetBetterer is offline   Reply With Quote
GetBetterer
View Public Profile
Find More Posts by GetBetterer
Reply

« Previous Thread | Next Thread »


Go Back   Talk Tennis > Miscellaneous > Odds & Ends
Reload this Page Help, somebody hack my website...

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 02:59 PM.

Talk Tennis :: Powered By Tennis Warehouse - Archive - Top

Powered by vBulletin® Version 3.6.9
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
© 2006 - Tennis Warehouse