Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Shared Hosting Support

Notices

Closed Thread
 
Thread Tools
  #1  
Old 12-17-2003, 09:02 AM
Nicotine Nicotine is offline
Hatchling Croc
 
Join Date: Jun 2003
Posts: 16
Default

every one of my sites on my nestico.com whm

PLEASE HELP ME
I am 20 years old hacker from east
europe
i am very ill and need money for
operation
thats why i defaced your webiste (as one of
many) - i hope you are not angry on me
even 1 USD is important for me ... please
donate me and/or tell your friends about be
also if you dont want to waste your money then
i can work and earn
but i need job - i am php/mysql programmist

if you want i can do every website in
php/mysql/dhtml technology
i just want to live - i dont want to
die
please help me
sorry for defacement - oryginal index file is
saved as index.old.yourindexfileextension

best regards
tiamak


if you want to help me please email at tiamak@anonymous.to for more details
  #2  
Old 12-17-2003, 10:56 AM
alexs alexs is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 1
Default

Your index files we're replaced with his index file so either up load a new one and problem fixed. Or, if your index files are in php you'll have to go into your ftp account and delete the .html files.

Alex
  #3  
Old 12-17-2003, 11:02 AM
Ed Ed is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 1
Default

Polite hacker, though. Saved the old index file. I deleted his 3 (.htm, .html, and .php) and restored the original one. Everything seems OK, but when I get home, I'll upload the whole site again to be sure. Also, change your passwords. May not make any difference if he came in a back door, but it never hurts. I thought my password was good (mixed characters, etc.), but apparently not good enough. Is there anything else we can do to secure our sites?
  #4  
Old 12-17-2003, 11:35 AM
CRySSiS's Avatar
CRySSiS CRySSiS is offline
Baby Croc
 
Join Date: Oct 2002
Location: Canada
Posts: 99
Default

Yes, make sure all scripts you run on your site are the most recent stable version.

Check on Google for things like "hacking [your script name here]". If anything comes up make sure it has nothing to do with the version you have. Also check the creater's site for any info they have on script security.

Don't give your password out, or anything else to that nature.
__________________
If the world was free, I would still be poor.
  #5  
Old 12-17-2003, 12:33 PM
Maven Maven is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 21
Default

I just checked one of my friends accounts here, I have a reseller account here referred by him. He auto-installed Invision Board 1.1.2 on a site on his account. The version the auto installer ran for him is missing security patches. I updated his board, maybe someone should update the installer? The topic on their site is here:

http://forums.invisionpower.com/inde...howtopic=78454

Cheers
  #6  
Old 12-17-2003, 12:37 PM
Maven Maven is offline
Hatchling Croc
 
Join Date: Dec 2003
Posts: 21
Default

There's also a vulnerability in ipchat.php, that the auto installer puts on the server. He doesn't use the chat, so I just deleted it. Maybe you should update the auto installer, or remove ipchat.php from the install.

The invision topic is here:

http://forums.invisionpower.com/inde...howtopic=77376

Hope this helps
  #7  
Old 12-17-2003, 01:11 PM
Nicotine Nicotine is offline
Hatchling Croc
 
Join Date: Jun 2003
Posts: 16
Default

They hit every one of my sites, even ones that only have an index html page and one image and nothing else. No scripts, nothing.

It looks like the hacker found a backdoor into our server(s) and planted their index files in the root.

It looks like Hostgator went ahead and restored all of my original HTML files back to the originals, saving us the trouble of doing it ourselves.

Thanks HOSTGATOR for fixing it so quickly!! This is one of the reasons I chose Hostgator to host my sites. A+ service.
  #8  
Old 12-17-2003, 01:37 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 3,006
Default

The hacker took advantage of a newly discovered vulnerability. It has since been patched and the affected files restored. The hackers ip has also been banned from the server.


First security incident we've ever had it affected a single server.
__________________
Gators love marshmallows.
  #9  
Old 12-17-2003, 04:44 PM
blutat2's Avatar
blutat2 blutat2 is offline
Hatchling Croc
 
Join Date: Jul 2003
Location: South Carolina
Posts: 3
Default

All my sites were hacked also. I only noticed when one of my customers pulled there site up today and there it was. Thanks Hostgator for the quick response.


Jack Beaman
SCSiteDesigns.com
MyAuctionsPlus.com
  #10  
Old 12-18-2003, 11:31 AM
CRySSiS's Avatar
CRySSiS CRySSiS is offline
Baby Croc
 
Join Date: Oct 2002
Location: Canada
Posts: 99
Default

Quote:
Originally Posted by Nicotine
They hit every one of my sites, even ones that only have an index html page and one image and nothing else. No scripts, nothing.

It looks like the hacker found a backdoor into our server(s) and planted their index files in the root.

It looks like Hostgator went ahead and restored all of my original HTML files back to the originals, saving us the trouble of doing it ourselves.

Thanks HOSTGATOR for fixing it so quickly!! This is one of the reasons I chose Hostgator to host my sites. A+ service.
All they have to do is get one site. Once they have that, they can do what ever they want.
__________________
If the world was free, I would still be poor.
  #11  
Old 12-18-2003, 01:34 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 3,006
Default

It was done using /tmp directory. They never had a single password, and got through using a customers insecure script.

He tried doing more damage but the server was secure enough from him being able to do much more then changing peoples indexes.

He's "hacked" 400 servers in two weeks time period including about 70k sites. We don't have 400 servers =)
Only porsche was affected till we ran the fix , patched the exploit (tmp),

We are working on getting horde and file manager to be exlclude but this might take a few days.
__________________
Gators love marshmallows.
  #12  
Old 12-18-2003, 09:05 PM
taylorcrowe taylorcrowe is offline
Hatchling Croc
 
Join Date: Dec 2003
Location: Philadelphia
Posts: 1
Default

Hi I'm new to Gator as well. But for the past four days I have had no problems uploading my site to your servers. Then today for no reason at all I cannot upload a single file or html using Dreamweaver, not sure if its because you were hacked or not, but another Gator member told me (make that two) that they cannot upload using dreamweaver as well. I need to know if the hacking is what caused the problem and if there is a fix. I unfortunately do not know how to use any other ftp's to upload my site. And Dreamweaver for me is userfriendly. Any help with this would be appreciated. Thanks again.
  #13  
Old 12-19-2003, 12:11 AM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 3,006
Default

No has nothing to do with it. Dreamweavers FTP works the same as any other ftp so if you can't connect something isn't configured right.

[/url]http://www.demodemo.com/tutorials_dreamweaver.htmlhttp://<br /> Go there to watch a m...f all problemshttp://www.demodemo.com/tutorials_dreamweaver.html
__________________
Gators love marshmallows.
Closed Thread

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
double optin - adult websites and pornography saturnus Pre-Sales Questions 8 08-17-2004 02:18 AM
2 Websites, one MySQL DB webmorpheus.com Pre-Sales Questions 0 04-03-2004 02:53 AM
Yow! E-mail getting hacked?! dcorwin Shared Hosting Support 1 12-03-2003 02:11 PM

All times are GMT -5. The time now is 03:44 AM.