| Author |
Topic Search Topic Options
|
yataylimit
Groupie
Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
|
Post Options
Thanks(0)
Quote Reply
Topic: My website was hacked - Nothing to do with WebWiz Posted: 23 May 2007 at 8:24am |
Hi guys.
Someone somehow uploaded an "index.html" file with a "Hacked by XXX" message to my space thereby causig the forum to malfunction. Is this a new hacking method? Has anyone ever experienced it? What should I do?
You can find the "index.html". file here if could be of any help, because it has a strange form.
Thanks.
Edited by yataylimit - 26 May 2007 at 8:14pm
|
 |
WebWiz-Bruce
Admin Group
Web Wiz Developer
Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 8:33am |
|
Web Wiz Forums itself is extreamly secure and a hacker can use many methods to place such a file on the server if your web site is not setup securely.
Before writting a 10 page esay on the many 1000's of different ways a hacker could have done this the best thing to do is have a look through your sites log files to findout exactly how the hacker has done this and what path through your site they took.
Also other information would be helful such as;
Web Wiz Forusm version? Database type? Are uploads enabled? Have you disabled write permissions to your public folders? (This would certainly stop this type of thing) Are your passwords sufficiently strong? (FTP, Frontpage, Forum Admin login)
|
|
|
 |
yataylimit
Groupie
Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 9:37am |
Ok Borg, thanks I will try them.
Sorry for the missing info:
- I use the latest Access version.
- Uploads were enabled but now I disabled them by removing all file extensions that can be uploaded.
- Write permissions were disabled now.
- Passwords are OK
|
 |
WebWiz-Bruce
Admin Group
Web Wiz Developer
Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 9:48am |
|
If you are using the Access version make sure that the database is in a secure folder without public access.
Incase the hacker has got hold of your database, if it was not properly secured, update any admin passwords straight away (you should do this anyway).
To disable uploads you should update the permissions system, although uploads are pretty secure, so I doubt they got in this way, more likely exploited the IIS web server by not have write permissions disabled.
Edited by -boRg- - 23 May 2007 at 9:50am
|
|
|
 |
yataylimit
Groupie
Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 10:15am |
Database is in a secure db folder above the root Borg. I have also contacted to the person responsible for the server to see if it has something to do with any possible hack on the server.
Thanks again.
|
 |
WebWiz-Bruce
Admin Group
Web Wiz Developer
Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 10:55am |
|
The best way is to look at your log files, you should be able to get from the modify or creation date of the file an estimate of the time the file was placed on the server.
Then it is just a case of looking in your log files for activity around this time, and the IP address of the hacker. By following the IP addresses back through your log files you should be able to see the files that the hacker has viewed and from these tell how, or what part of the site the hacker used to place the file on the server, or what method they used.
|
|
|
 |
yataylimit
Groupie
Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
|
Post Options
Thanks(0)
Quote Reply
Posted: 23 May 2007 at 12:30pm |
Well, I examined log files and found that:
2007-05-23 00:40:07 W3SVC5125 HAYATSERVER 80.93.208.116 HEAD /index.html - 80 - 65.36.241.79 HTTP/1.1 InternetSeer.com - - "My Domain Name" 200 0 0 326 93 125
This occurs in every few hours with index.htm, index.asp and other similar extensions. However, the relevant IP has no other activity. By the way, I don't know what this internetseer.com is...
Now, I limited my starting page to be only default.asp. I don't know if it helps.
Thanks.
Edited by yataylimit - 23 May 2007 at 12:32pm
|
 |
ruycnd
Newbie
Joined: 28 March 2007
Status: Offline
Points: 14
|
Post Options
Thanks(0)
Quote Reply
Posted: 26 May 2007 at 10:32am |

Edited by ruycnd - 07 July 2011 at 6:49am
|
 |