Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Turkish hacker.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Turkish hacker.

 Post Reply Post Reply Page  12>
Author
Lynford View Drop Down
Groupie
Groupie


Joined: 14 December 2004
Status: Offline
Points: 171
Post Options Post Options   Thanks (0) Thanks(0)   Quote Lynford Quote  Post ReplyReply Direct Link To This Post Topic: Turkish hacker.
    Posted: 29 October 2005 at 3:20pm
Sorry if this has been done before, but I have been hacked Cry
 
I have not used all of Borg's anti-hacking measures partly due to the fact that I am new to all this and don't understand some of it Embarrassed
 
Right, so I have been hacked - I have deleted (and replaced with a new downloaded version) all forum files from my server and replaced my Database with a backup that I made this morning. I still have that bloody hackers logo up though. What have I done wrong, or what else should I delete please ?
 
Thanks for any help Big smile Why do these twats do this ? Angry
Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 5:04am
can you paste a link so we can see if its a WebWiz hack or server hack

it maybe they have uplaoded files to the server
Back to Top
Lynford View Drop Down
Groupie
Groupie


Joined: 14 December 2004
Status: Offline
Points: 171
Post Options Post Options   Thanks (0) Thanks(0)   Quote Lynford Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 5:09am
Originally posted by dj air dj air wrote:

can you paste a link so we can see if its a WebWiz hack or server hack

it maybe they have uplaoded files to the server
 
Thanks for your help DJ Big smile
 
 
Would you need a login account ?
Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 5:16am
ok it does seem to be a WebWiz hack

you need ot go to the admin configuration area and change the top image url to something else or nothing


to avoid this:

  1. don't allow image or file uploading unless you know the person well
  2. make sure your password is atleast 8 charecters and letters and numbers and not directory word like hello etc
  3. make sure your database is outside the root folder so it cant be accessed
  4. failing 3. change the path to the database to .asp not .mdb and change the name of the database to .asp not .mdb
there are some ideas
Back to Top
Lynford View Drop Down
Groupie
Groupie


Joined: 14 December 2004
Status: Offline
Points: 171
Post Options Post Options   Thanks (0) Thanks(0)   Quote Lynford Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 5:55am
Thanks DJ, you are a star. For No3, what do you mean by the root folder please (As I said, I'm quite new to this)
In my FTP prog I have 3 folders at the very start - htdocs / Logfiles / Private. Should it be in one of those ?
 
My Folder forum is in htdocs
 
Thanks again for your help Big smile
Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 7:00am
you want to place the database in the private folder then set the path within the common.asp files to the physical path


E:\domains\yourdomain\private\forum.mdb

example

you can get the physical path from your webhost or use

response.write server.mappath("../../private/forum.mdb")


note the above may be dis allowed, but your host will know

Back to Top
Hogmanus View Drop Down
Newbie
Newbie


Joined: 29 October 2005
Status: Offline
Points: -3
Post Options Post Options   Thanks (0) Thanks(0)   Quote Hogmanus Quote  Post ReplyReply Direct Link To This Post Posted: 30 October 2005 at 9:55am
I too got hacked by the Turks.
They got in via the upload facility and placed 2 files on the server Zephir and hacktool.
They then used this to creat a default and index page with every extension ( htm, html, asp, cfm and php ) creating a total of five default and five index pages in each folder with my site including the log folder and private.
 
There are 4056 pages hosted on my site withn 53 subfolders (yes its a big site) You can imagine the horror I am faced with deleting all the extra files and restoring the site to its former glory. If it was a standard static site it wouldnt be too bad but as its live data (League tables etc) its not that easy.
11 hours yesterday and not finished yet.... Oh dear
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 31 October 2005 at 8:34am
It sounds like you left your site open to hackers by not disabling write permissions.

With write permissions enabled a hacker doesn't need to use the forum to hack your site, they can simply manipulate HTTP to upload files to the server writing any files they want in any folder that has write permissions.

As the latest version doesn't use the ADO.Stream object you should also consider disabling this as there is a security hole in this object that means by changing HTTP headers to 'PUT' files can be placed anywhere within your site.
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.