Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - My website was hacked - Nothing to do with WebWiz
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

My website was hacked - Nothing to do with WebWiz

 Post Reply Post Reply Page  12>
Author
yataylimit View Drop Down
Groupie
Groupie
Avatar

Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
Post Options Post Options   Thanks (0) Thanks(0)   Quote yataylimit Quote  Post ReplyReply Direct Link To This Post Topic: My website was hacked - Nothing to do with WebWiz
    Posted: 23 May 2007 at 8:24am
Hi guys.
 
Someone somehow uploaded an "index.html" file with a "Hacked by XXX" message to my space thereby causig the forum to malfunction. Is this a new hacking method? Has anyone ever experienced it? What should I do?
 
You can find the "index.html". file here if could be of any help, because it has a strange form.
 
Thanks.  


Edited by yataylimit - 26 May 2007 at 8:14pm
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 8:33am
Web Wiz Forums itself is extreamly secure and a hacker can use many methods to place such a file on the server if your web site is not setup securely.

Before writting a 10 page esay on the many 1000's of different ways a hacker could have done this the best thing to do is have a look through your sites log files to findout exactly how the hacker has done this and what path through your site they took.

Also other information would be helful such as;

Web Wiz Forusm version?
Database type?
Are uploads enabled?
Have you disabled write permissions to your public folders? (This would certainly stop this type of thing)
Are your passwords sufficiently strong? (FTP, Frontpage, Forum Admin login)
Back to Top
yataylimit View Drop Down
Groupie
Groupie
Avatar

Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
Post Options Post Options   Thanks (0) Thanks(0)   Quote yataylimit Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 9:37am

Ok Borg, thanks I will try them.

Sorry for the missing info:
- I use the latest Access version.
- Uploads were enabled but now I disabled them by removing all file extensions that can be uploaded.
 - Write permissions were disabled now.
- Passwords are OK
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 9:48am
If you are using the Access version make sure that the database is in a secure folder without public access.

Incase the hacker has got hold of your database, if it was not properly secured, update any admin passwords straight away (you should do this anyway).

To disable uploads you should update the permissions system, although uploads are pretty secure, so I doubt they got in this way, more likely exploited the IIS web server by not have write permissions disabled.


Edited by -boRg- - 23 May 2007 at 9:50am
Back to Top
yataylimit View Drop Down
Groupie
Groupie
Avatar

Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
Post Options Post Options   Thanks (0) Thanks(0)   Quote yataylimit Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 10:15am
Database is in a secure db folder above the root Borg. I have also contacted to the person responsible for the server to see if it has something to do with any possible hack on the server.  
Thanks again.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 10:55am
The best way is to look at your log files, you should be able to get from the modify or creation date of the file an estimate of the time the file was placed on the server.

Then it is just a case of looking in your log files for activity around this time, and the IP address of the hacker. By following the IP addresses back through your log files you should be able to see the files that the hacker has viewed and from these tell how, or what part of the site the hacker used to place the file on the server, or what method they used.
Back to Top
yataylimit View Drop Down
Groupie
Groupie
Avatar

Joined: 23 April 2002
Location: United States
Status: Offline
Points: 82
Post Options Post Options   Thanks (0) Thanks(0)   Quote yataylimit Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2007 at 12:30pm

Well, I examined log files and found that:

2007-05-23 00:40:07 W3SVC5125 HAYATSERVER 80.93.208.116 HEAD /index.html - 80 - 65.36.241.79 HTTP/1.1 InternetSeer.com - - "My Domain Name" 200 0 0 326 93 125
 
This occurs in every few hours with index.htm, index.asp and other similar extensions. However, the relevant IP has no other activity. By the way, I don't know what this internetseer.com is...
 
Now, I limited my starting page to be only default.asp. I don't know if it helps.
 
Thanks.  


Edited by yataylimit - 23 May 2007 at 12:32pm
Back to Top
ruycnd View Drop Down
Newbie
Newbie


Joined: 28 March 2007
Status: Offline
Points: 14
Post Options Post Options   Thanks (0) Thanks(0)   Quote ruycnd Quote  Post ReplyReply Direct Link To This Post Posted: 26 May 2007 at 10:32am
Wink


Edited by ruycnd - 07 July 2011 at 6:49am
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.