Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-26-2008, 04:00 PM
Francisco Francisco is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Account Hacked or just index page?

Hi, one of my clients site was hacked and his index page was replaced with this:

[Collaps3 CREW] H4ck you!

What´s up admin? seens not well right?

No data lost but next time if you see me lauphing you better have a nice backup!

We are Observing Vini4p cannabis DD3str0y3r

if you wanna contact us use a mirc script and go to

/server -m irc.chatbr.org #Collaps3

mirc r0x msn sux!

.::by observing::.



Any ideas how they did this? is a windows server with php enable, Fix IP and anon ftp active.

They use a script? or they really hack account password?
__________________
Francisco
Reply With Quote
  #2  
Old 01-26-2008, 05:56 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
What software was powering the site, if you had anything like joomla, phpbb or other common package that was not patched and up to date then that's probably how .. just check the logs is all you'll really need to do to work out how probably.
Reply With Quote
  #3  
Old 01-26-2008, 07:18 PM
Francisco Francisco is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
No package at all just plain htm files and php script for speed test.
__________________
Francisco
Reply With Quote
  #4  
Old 01-26-2008, 10:41 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
There had to be some way in, have you checked the logs thoroughly ? It could have been brute force, there is that Apache bot going around currently which uses brute force I believe but you've stated this was Windows so I very much doubt that was it.

I would highly suggest the owner of the site checks their computer for Malware and sypware etc becuase that's another way they could have gotten the password.
Reply With Quote
  #5  
Old 01-27-2008, 11:36 AM
Francisco Francisco is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Thanks, lets check that.
__________________
Francisco
Reply With Quote
  #6  
Old 01-28-2008, 04:14 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
also a good practice to cycle out your Hsphere/FTP passwords often. How often depends on you - but I had several sites hacked, always on the same server, several years ago. Got on a 2-week password rotation and has been fine ever since.

Also, make sure your passwords are strong. My rule? Minimum 12 characters, alpha-num, plus dash or underscore.

Given time, any jackass can crack your password if you keep it the same for long enough.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
to make index.php as default page gmsi Chit Chat Public 7 11-28-2005 08:05 AM
Customer account hacked! kattouf Chit Chat Public 22 05-20-2005 12:20 PM
index page outercircle H-Sphere Pre-Sales 6 07-18-2003 02:38 PM


All times are GMT -5. The time now is 04:20 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.50580 seconds with 16 queries
[Output: 59.64 Kb. compressed to 55.44 Kb. by saving 4.20 Kb. (7.05%)]