<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : forum hacked</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : forum hacked]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Wed, 08 Apr 2026 19:44:14 +0000</pubDate>
  <lastBuildDate>Tue, 20 Jul 2004 05:05:49 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=11239</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[forum hacked : Doesn&amp;#039;t sound like any bug....]]></title>
   <link>https://forums.webwiz.net/forum-hacked_topic11239_post62073.html#62073</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=9949">dpyers</a><br /><strong>Subject:</strong> 11239<br /><strong>Posted:</strong> 20&nbsp;July&nbsp;2004 at 5:05am<br /><br /><P>Doesn't sound like any bug. Sounds like you've left access and write permissions on your directory structure open to eveyone.&nbsp;</P><P>Warez groups like to find people who have set up their web security badly. WWF uses a commonly known directory structure so they know where they can put things. Your IP address has probably been broadcast all over the web to people who are using your bandwidth to download CD's and are probably using your space to add more illicit stuff. You need to secure this immediately.</P><P>You need to lockdown ftp and make sure you don't allow anonymous access to any directories. Web directories with scripts should only allow execute permissions to IUSR_xxxx.</P><P>If you're running off of your own server, get all the MS patches and the MS IIS Lockdown Tool. Should also do virus and spyware scans.</P><P>If you're using shared hosting, contact your host and explain the situation to them. Follow their recommendations for securing the site.&nbsp; They may give you a break on any bandwidth overage charges if you act promptly.</P>]]>
   </description>
   <pubDate>Tue, 20 Jul 2004 05:05:49 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/forum-hacked_topic11239_post62073.html#62073</guid>
  </item> 
  <item>
   <title><![CDATA[forum hacked : This won&amp;#039;t have anything...]]></title>
   <link>https://forums.webwiz.net/forum-hacked_topic11239_post62070.html#62070</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 11239<br /><strong>Posted:</strong> 20&nbsp;July&nbsp;2004 at 4:43am<br /><br />This won't have anything to do with Web Wiz Forums.<br><br>The problem is that IIS is unsecure unless you use the IIS lockdown tool available from Microsoft.<br><br>You have probally left write permissions enabled on all directorieswithin your web site, this then allows a hacker to write to thosedirectories, which is by the sound of it has happened.<br><br>If you are using the Access version of web wiz forums you should placethe database outside of your web site in a directory that is notaccessiable with a web browser (there are instructions on how to dothis with the software)<br><br>The directory containg the database should be the only one with writepermissions, all other directories give them read only permisisons forthe IUSR account on your system.<br>]]>
   </description>
   <pubDate>Tue, 20 Jul 2004 04:43:07 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/forum-hacked_topic11239_post62070.html#62070</guid>
  </item> 
  <item>
   <title><![CDATA[forum hacked : hi,first off:I am new to asp, I...]]></title>
   <link>https://forums.webwiz.net/forum-hacked_topic11239_post62067.html#62067</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=16780">martink</a><br /><strong>Subject:</strong> 11239<br /><strong>Posted:</strong> 20&nbsp;July&nbsp;2004 at 3:51am<br /><br /><P>hi,first off:I am new to asp,</P><P>I have a web wiz forum running on my website,IIs 6.0,w2k server.</P><P>what I have discovered:</P><P>they set up a directory under/forum/admin/include called 'temp'</P><P>there they saved 1 game cd,files were hidden.</P><P>then in the root directory of the web partition they left one folder </P><P>named </P><PRE>ÿÿ-;; &amp;20 @tagged .by; quit %f;;...-ÿÿ</PRE><PRE>with about 20 folders inside each other.(I guess to make obviuos ,that they 'were here'</PRE><PRE>so:how could they get write access on my D: partition,</PRE><PRE>do you think they came through the forum?my website is under construction,</PRE><PRE>one static picture without even a link to the forum.</PRE><PRE>or did they exploit a windows/IIS bug.</PRE><PRE>&nbsp;</PRE><PRE>any comment appreciated,</PRE><PRE>m</PRE>]]>
   </description>
   <pubDate>Tue, 20 Jul 2004 03:51:27 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/forum-hacked_topic11239_post62067.html#62067</guid>
  </item> 
 </channel>
</rss>