<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Turkish hacker.</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Turkish hacker.]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 18 Apr 2026 12:32:42 +0000</pubDate>
  <lastBuildDate>Tue, 01 Nov 2005 15:22:23 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=17075</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Turkish hacker. : I don&amp;#039;t think most web site...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post93114.html#93114</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=19649">JJLatWebWiz</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 01&nbsp;November&nbsp;2005 at 3:22pm<br /><br />I don't think most web site admins are going to have the option to disable ADODB.Stream as it would probably have to be disabled for entire server hosting hundreds of other sites.<br /><br />However, I think the security flaws in ADODB.Stream actually compromise the <em>client</em> when combined with flaws with Internet Explorer.  The ADODB.Stream/IE security flaws allow a web page to execute script on the client machine in the Local Machine internet zone.  <br /><br />The Turkish hacker utility that I've seen doesn't exploit any unintentional security bugs or flaws.  It will work on ANY server that uses ANY enabled version of the ADODB.Stream and no correction of unintensional flaws therein will hinder this hacker utility.  Only server administrators using best practice security configurations can stop this utility from working.<br /><br />Even a flawed ADODB.Stream is working with the security rights of the anonymous web user, so ADODB.Stream can be used to upload files ONLY to folders to which the anonymous user has such permission.<br /><br />Of course, there are always other security flaws and poor server configurations that could be exploited to change that, but WWF is required or even useful for any of this hacking.  And don't let your host tell you that by using WWF, it was your fault that the server was compromised.]]>
   </description>
   <pubDate>Tue, 01 Nov 2005 15:22:23 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post93114.html#93114</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : It sounds like you left your site...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post93017.html#93017</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 31&nbsp;October&nbsp;2005 at 8:34am<br /><br />It sounds like you left your site open to hackers by not disabling write permissions.<br><br>With write permissions enabled a hacker doesn't need to use the forumto hack your site, they can simply manipulate HTTP to upload files tothe server writing any files they want in any folder that has writepermissions.<br><br>As the latest version doesn't use the ADO.Stream object you should alsoconsider disabling this as there is a security hole in this object thatmeans by changing HTTP headers to 'PUT' files can be placed anywherewithin your site.<br>]]>
   </description>
   <pubDate>Mon, 31 Oct 2005 08:34:33 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post93017.html#93017</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : I too got hacked by the Turks. They...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92978.html#92978</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=22155">Hogmanus</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 9:55am<br /><br />I too got hacked by the Turks.<DIV>They got in via the upload facility and placed 2 files on the server Zephir and hacktool.</DIV><DIV>They then used this to creat a default and index page with every extension ( htm, html, asp, cfm and php ) creating a total of&nbsp;five default and five index pages in each folder with my site including the log folder and private.</DIV><DIV>&nbsp;</DIV><DIV>There are 4056 pages hosted on my site withn 53 subfolders (yes its a big site) You can imagine the horror I am faced with deleting all the extra files and restoring the site to its former glory. If it was a standard static site it wouldnt be too bad but as its live data (League tables etc) its not that easy.</DIV><DIV>11 hours yesterday and not finished yet.... Oh dear</DIV>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 09:55:06 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92978.html#92978</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : you want to place the database...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92967.html#92967</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 7:00am<br /><br />you want to place the database in the private folder then set the path within the common.asp files to the physical path<br><br><br>E:\domains\yourdomain\private\forum.mdb<br><br>example<br><br>you can get the physical path from your webhost or use <br><br>response.write server.mappath("../../private/forum.mdb")<br><br><br>note the above may be dis allowed, but your host will know<br><br>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 07:00:39 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92967.html#92967</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : Thanks DJ, you are a star. For...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92962.html#92962</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18669">Lynford</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 5:55am<br /><br />Thanks DJ, you are a star. For No3, what do you mean by the root folder please (As I said, I'm quite new to this)<DIV>In my FTP prog I have 3 folders at the very start - <strong>htdocs / Logfiles / Private. </strong>Should it be in one of those ?</DIV><DIV>&nbsp;</DIV><DIV>My Folder forum is in <strong>htdocs</strong></DIV><DIV>&nbsp;</DIV><DIV>Thanks again for your help <IMG height=17 alt="Big smile" src="http://forums.webwiz.net/smileys/smiley4.gif" width=17 align=absMiddle border="0"></DIV>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 05:55:13 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92962.html#92962</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : ok it does seem to be a WebWiz...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92961.html#92961</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 5:16am<br /><br />ok it does seem to be a WebWiz hack<br><br>you need ot go to the admin configuration area and change the top image url to something else or nothing<br><br><br>to avoid this:<br><br><ol>  <li>don't allow image or file uploading unless you know the person well</li>  <li>make sure your password is atleast 8 charecters and letters and numbers and not directory word like hello etc</li>  <li>make sure your database is outside the root folder so it cant be accessed</li>  <li>failing 3. change the path to the database to .asp not .mdb and change the name of the database to .asp not .mdb</li></ol>there are some ideas<br>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 05:16:34 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92961.html#92961</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. :   dj air wrote:can you paste...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92960.html#92960</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18669">Lynford</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 5:09am<br /><br /><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by dj air" alt="Originally posted by dj air" style="vertical-align: text-bottom;" /> <strong>dj air wrote:</strong><br /><br />can you paste a link so we can see if its a WebWiz hack or server hack<BR><BR>it maybe they have uplaoded files to the server<BR></td></tr></table> <DIV>&nbsp;</DIV><DIV>Thanks for your help DJ <IMG height=17 alt="Big smile" src="http://forums.webwiz.net/smileys/smiley4.gif" width=17 align=absMiddle border="0"></DIV><DIV>&nbsp;</DIV><DIV>The forums can be found at <A title=here href="http://www.fromthelane.co.uk/forum/default.asp" target="_blank">http://www.fromthelane.co.uk/forum/default.asp</A></DIV><DIV>&nbsp;</DIV><DIV>Would you need a login account ?</DIV>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 05:09:40 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92960.html#92960</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : can you paste a link so we can...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92957.html#92957</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=2216">dj air</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 30&nbsp;October&nbsp;2005 at 5:04am<br /><br />can you paste a link so we can see if its a WebWiz hack or server hack<br><br>it maybe they have uplaoded files to the server<br>]]>
   </description>
   <pubDate>Sun, 30 Oct 2005 05:04:22 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92957.html#92957</guid>
  </item> 
  <item>
   <title><![CDATA[Turkish hacker. : Sorry if this has been done before,...]]></title>
   <link>https://forums.webwiz.net/turkish-hacker_topic17075_post92934.html#92934</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=18669">Lynford</a><br /><strong>Subject:</strong> 17075<br /><strong>Posted:</strong> 29&nbsp;October&nbsp;2005 at 3:20pm<br /><br />Sorry if this has been done before, but I have been hacked <IMG height=17 alt=Cry src="http://forums.webwiz.net/smileys/smiley19.gif" width=17 align=absMiddle border="0"><DIV>&nbsp;</DIV><DIV>I have not used all of Borg's anti-hacking measures partly due to the fact that I am new to all this and don't understand some of it <IMG height=17 alt=Embarrassed src="http://forums.webwiz.net/smileys/smiley9.gif" width=17 align=absMiddle border="0"></DIV><DIV>&nbsp;</DIV><DIV>Right, so I have been hacked - I have deleted&nbsp;(and replaced with a new downloaded version)&nbsp;all forum files from my server and replaced my Database with a backup that I made this morning. I still have that bloody hackers logo up though. What have I done wrong, or what else should I delete please ?</DIV><DIV>&nbsp;</DIV><DIV>Thanks for any help <IMG height=17 alt="Big smile" src="http://forums.webwiz.net/smileys/smiley4.gif" width=17 align=absMiddle border="0">&nbsp;Why do these twats do this ? <IMG height=17 alt=Angry src="http://forums.webwiz.net/smileys/smiley7.gif" width=17 align=absMiddle border="0"></DIV>]]>
   </description>
   <pubDate>Sat, 29 Oct 2005 15:20:50 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/turkish-hacker_topic17075_post92934.html#92934</guid>
  </item> 
 </channel>
</rss>