Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 07-02-2008, 06:07 PM
Ablaze Ablaze is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Talking I wanna fry me a damn Turkey! Hacker that is!

I have a client on a Unix server that keeps getting Hacked over and over again.

It has happened to more than one of his domains on his account.

It has happened to one site in particular three times in the last 6 months.

I Searched the forum and only found information about the mentality of the hackers but not a way to stop them.

Some of the sites were created with Sitestudio...
OsCommerce is one of the sites as well...
Any known vulnerabilites on either of them that you know of???

Any suggestions on what script I should look for that is allowing this Turkish fellow from hacking his site and deleting all his files?

Anybody else had this problem recently?

Any help would be very much appreciated!

Thanks,

B-
Reply With Quote
  #2  
Old 07-02-2008, 08:36 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
is it being injected with the old b.js script or similar ? having a few of them crop up recently myself too but then there is a pretty big wave of hacks going on currently too.

Out of interest what server is this client on? (mine I think is on NT5)
Reply With Quote
  #3  
Old 07-02-2008, 11:01 PM
Ablaze Ablaze is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Quote:
Originally Posted by Brangwyn
is it being injected with the old b.js script or similar ? having a few of them crop up recently myself too but then there is a pretty big wave of hacks going on currently too.

Out of interest what server is this client on? (mine I think is on NT5)

Unix16...

So is b.js or similar script something that is used by site studio and/or oscommerce?

Is there any hope in removing the vulnerability so that it does not continue to happen? Luckily this particular client uses Site studio quite a bit so he is able to just log in and re-publish.

I appreciate your quick response time Brangwyn...

Last edited by Ablaze : 07-02-2008 at 11:06 PM.
Reply With Quote
  #4  
Old 07-03-2008, 12:03 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Do a google for ASPROX which is probably the most prolifient Trojan at the moment that's doing botnetted attacks like this.

I'm not really sure at this stage how it would be effecting sites that aren't using SQL Somewhere but I've one customer that I mentioned above who's had similar and he seems to have just a few HTML pages with Flash imbedded

http://www.secureworks.com/research/...t=danmecasprox
Reply With Quote
  #5  
Old 07-03-2008, 08:49 AM
dpyers's Avatar
dpyers dpyers is online now
Vortech Inc. Customer
Vortech Inc. Customer
 
If all files have been removed from multiple web sites running different software a couple of times and you've changed the account password, There's a good chance that a Trojan on the clients machine is the bad guy.
__________________
Reply With Quote
  #6  
Old 07-03-2008, 10:26 AM
Ablaze Ablaze is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
I appreciate your help gentleman!

Here is a copy of an email that I sent to my client...

Quote:
Jeremy - check an see if these values are in your registry of all the computers that you use:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\aspimgr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Sft

Also

Check in your services and see if you have a service called: msscntr32.exe

I have been told that there is a good chance that the attacks to your site are coming from your computer. The reason they told me that is because you have changed your ftp passwords multiple times on your sites and they keep getting hacked.

Read this: http://www.secureworks.com/research/...t=danmecasprox
Do a search for ASPROX in google for additional info.

Let me know if any of the above keys and/or files are running on your systems so that I may start looking for directions on how to remove them.

Any additional suggestions would be appreciated. I will report back to you all if he finds any of the above suggested registry keys and/or services.

Thanks!

Last edited by Ablaze : 07-03-2008 at 10:31 AM.
Reply With Quote
  #7  
Old 07-03-2008, 04:56 PM
dpyers's Avatar
dpyers dpyers is online now
Vortech Inc. Customer
Vortech Inc. Customer
 
Let us know how it turns out.
__________________
Reply With Quote
  #8  
Old 07-03-2008, 05:08 PM
Ablaze Ablaze is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Will do...
Reply With Quote
  #9  
Old 07-03-2008, 05:35 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
I have a site I'm getting a lot of attempted sql injections.

hehe just for fun we decoded the attack and re-wrote it and re-encoded it to create a sql injection fix
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #10  
Old 07-03-2008, 11:25 PM
Danl Danl is offline
Administrator
Admin
 
Haha, glad to hear we finally have some people that are combating these idiots who think it's okay to ruin other people's hard work, Silverbug, if you have any suggestions please let us know so we can tell some of our clients that aren't using the forum's.
Reply With Quote
  #11  
Old 07-04-2008, 07:07 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
I would like to make one simple suggestion to Vortech actually, please consider installing the latest URLScan 3 beta and put a couple of simple deny rules in there to stop the attacks from even hitting our sites
Reply With Quote
  #12  
Old 07-04-2008, 08:31 AM
Danl Danl is offline
Administrator
Admin
 
I'll bring that up on Monday after the 4th of July weekend, thanks as always Brangwyn
Reply With Quote
  #13  
Old 07-04-2008, 09:19 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
I have a ruleset which seems to block the current wave of SQL Injection attacks quite nicely too if you're interested
Reply With Quote
  #14  
Old 09-03-2008, 03:33 PM
Ablaze Ablaze is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Danl,

What were the results of your Monday morning meeting in regards to Brangwyn's suggestion?

Thanks,

B-
Reply With Quote
  #15  
Old 09-03-2008, 03:42 PM
Danl Danl is offline
Administrator
Admin
 
Wow, I completely forgot about that apparently. I'll bring this up to everybody whenever they let me come back to work (been sick and outta work for a week). Thanks for bringing it back up to me Ablaze
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hacker: 180,000 attacks since 2003 PeterD Chit Chat Public 1 02-16-2007 11:41 AM
I wanna be #1 bubba Chit Chat Public 3 12-17-2005 01:16 PM
How do you like your turkey? awen Chit Chat Public 2 11-25-2004 11:03 AM
Its Snowing up here - damn nhdonny Chit Chat Public 19 03-16-2004 11:23 PM


All times are GMT -5. The time now is 05:11 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.68816 seconds with 17 queries
[Output: 110.81 Kb. compressed to 101.79 Kb. by saving 9.02 Kb. (8.14%)]