![]() |
|
|||||||
| Chit Chat Public Talk about any thing you want! This forum is public. |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
|||||||||||
|
|||||||||||
|
I have a client on a Unix server that keeps getting Hacked over and over again.
It has happened to more than one of his domains on his account. It has happened to one site in particular three times in the last 6 months. I Searched the forum and only found information about the mentality of the hackers but not a way to stop them. Some of the sites were created with Sitestudio... OsCommerce is one of the sites as well... Any known vulnerabilites on either of them that you know of??? Any suggestions on what script I should look for that is allowing this Turkish fellow from hacking his site and deleting all his files? Anybody else had this problem recently? Any help would be very much appreciated! Thanks, B- |
|
#2
|
|||||||||||
|
|||||||||||
|
is it being injected with the old b.js script or similar ? having a few of them crop up recently myself too but then there is a pretty big wave of hacks going on currently too.
Out of interest what server is this client on? (mine I think is on NT5) |
|
#3
|
|||||||||||
|
|||||||||||
|
Quote:
Unix16... So is b.js or similar script something that is used by site studio and/or oscommerce? Is there any hope in removing the vulnerability so that it does not continue to happen? Luckily this particular client uses Site studio quite a bit so he is able to just log in and re-publish. I appreciate your quick response time Brangwyn... Last edited by Ablaze : 07-02-2008 at 10:06 PM. |
|
#4
|
|||||||||||
|
|||||||||||
|
Do a google for ASPROX which is probably the most prolifient Trojan at the moment that's doing botnetted attacks like this.
I'm not really sure at this stage how it would be effecting sites that aren't using SQL Somewhere but I've one customer that I mentioned above who's had similar and he seems to have just a few HTML pages with Flash imbedded http://www.secureworks.com/research/...t=danmecasprox |
|
#5
|
||||||||||||
|
||||||||||||
|
If all files have been removed from multiple web sites running different software a couple of times and you've changed the account password, There's a good chance that a Trojan on the clients machine is the bad guy.
__________________
|
|
#6
|
|||||||||||
|
|||||||||||
|
I appreciate your help gentleman!
Here is a copy of an email that I sent to my client... Quote:
Any additional suggestions would be appreciated. I will report back to you all if he finds any of the above suggested registry keys and/or services. Thanks! Last edited by Ablaze : 07-03-2008 at 09:31 AM. |
|
#7
|
||||||||||||
|
||||||||||||
|
Let us know how it turns out.
__________________
|
|
#8
|
|||||||||||
|
|||||||||||
|
Will do...
|
|
#9
|
||||
|
||||
|
I have a site I'm getting a lot of attempted sql injections.
hehe just for fun we decoded the attack and re-wrote it and re-encoded it to create a sql injection fix ![]() |
|
#10
|
|||||||||||
|
|||||||||||
|
Haha, glad to hear we finally have some people that are combating these idiots who think it's okay to ruin other people's hard work, Silverbug, if you have any suggestions please let us know so we can tell some of our clients that aren't using the forum's.
|
|
#11
|
|||||||||||
|
|||||||||||
|
I would like to make one simple suggestion to Vortech actually, please consider installing the latest URLScan 3 beta and put a couple of simple deny rules in there to stop the attacks from even hitting our sites
![]() |
|
#12
|
|||||||||||
|
|||||||||||
|
I'll bring that up on Monday after the 4th of July weekend, thanks as always Brangwyn
|
|
#13
|
|||||||||||
|
|||||||||||
|
I have a ruleset which seems to block the current wave of SQL Injection attacks quite nicely too if you're interested
![]() |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Hacker: 180,000 attacks since 2003 | PeterD | Chit Chat Public | 1 | 02-16-2007 10:41 AM |
| I wanna be #1 | bubba | Chit Chat Public | 3 | 12-17-2005 12:16 PM |
| How do you like your turkey? | awen | Chit Chat Public | 2 | 11-25-2004 10:03 AM |
| Its Snowing up here - damn | nhdonny | Chit Chat Public | 19 | 03-16-2004 10:23 PM |