|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
A university server that I work on quite a bit has been attacked. I am wondering if anyone can give me more information on this kind of attack. A number of PHP pages seem to be replaced with a page that has the following text on it:
Anti - France We don't need AB(D) to make something. Make Sure : Your system is secure The nasty image on the page says: Hacked by Buster Here is the URL of a page that has been replaced by the page I've described above: -- link removed by admin -- I provided the description above as I hope that the SysAdmin will get rid of the hacked page very soon, making this URL not quite as interesting. Thank you. |
|
|||
|
I was finally able to connect to the server in question with my SSH client and I see that all of my PHP files are in their usual places, but still, the hacker's page was appearing instead of any file I would try to load from certain directories.
|
|
|||
|
If there is config.php, configuration.php, config.inc etc. or other important files on server, you must check them. For security you must change the files CHMOD.
You can change CHMOD 744 for all files. So Hackers or lamers don't change your files. Can you send me hacked site? (PM) |
|
|||
|
No, sorry, can't send along the URL. My SysAdmin would have a heart attack if I did. Thanks for the tip on the config files, though. I know exactly how the hackers got into the server now. It was through a PHP include statement where they could set the path to whatever they wanted.
|
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |