iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-16-2006, 12:06 PM
WebProWorld New Member
 
Join Date: Oct 2006
Location: Hamilton, ON, CA
Posts: 14
mohsho RepRank 0
Default Server "Hacked by Buster"

A university server that I work on quite a bit has been attacked. I am wondering if anyone can give me more information on this kind of attack. A number of PHP pages seem to be replaced with a page that has the following text on it:

Anti - France

We don't need AB(D) to make something.

Make Sure : Your system is secure

The nasty image on the page says:

Hacked by Buster

Here is the URL of a page that has been replaced by the page I've described above:

-- link removed by admin --

I provided the description above as I hope that the SysAdmin will get rid of the hacked page very soon, making this URL not quite as interesting.

Thank you.
Reply With Quote
  #2 (permalink)  
Old 10-16-2006, 03:41 PM
dharrison's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: May 2005
Location: Essex, UK
Posts: 1,289
dharrison RepRank 4dharrison RepRank 4dharrison RepRank 4
Default

Link removed as requested.
__________________
Deb Harrison
DVH Design
Essex Web Design
Reply With Quote
  #3 (permalink)  
Old 10-16-2006, 03:50 PM
WebProWorld New Member
 
Join Date: Oct 2006
Location: Hamilton, ON, CA
Posts: 14
mohsho RepRank 0
Default

I was finally able to connect to the server in question with my SSH client and I see that all of my PHP files are in their usual places, but still, the hacker's page was appearing instead of any file I would try to load from certain directories.
Reply With Quote
  #4 (permalink)  
Old 10-19-2006, 04:27 PM
WebProWorld New Member
 
Join Date: Oct 2006
Posts: 2
Mustaf RepRank 0
Default

If there is config.php, configuration.php, config.inc etc. or other important files on server, you must check them. For security you must change the files CHMOD.

You can change CHMOD 744 for all files. So Hackers or lamers don't change your files.

Can you send me hacked site? (PM)
Reply With Quote
  #5 (permalink)  
Old 10-19-2006, 04:32 PM
WebProWorld New Member
 
Join Date: Oct 2006
Location: Hamilton, ON, CA
Posts: 14
mohsho RepRank 0
Default

No, sorry, can't send along the URL. My SysAdmin would have a heart attack if I did. Thanks for the tip on the config files, though. I know exactly how the hackers got into the server now. It was through a PHP include statement where they could set the path to whatever they wanted.
Reply With Quote
  #6 (permalink)  
Old 10-19-2006, 04:37 PM
WebProWorld New Member
 
Join Date: Oct 2006
Posts: 2
Mustaf RepRank 0
Default

You can check your scripts to exploit or include statement.
Example: Your script is Php-Nuke.
"Phpnuke include" etc...
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 04:17 PM.



Search Engine Optimization by vBSEO 3.3.0