Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - New Turkish Hacker Trick.
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

New Turkish Hacker Trick.

 Post Reply Post Reply Page  <12345 7>
Author
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 9:42am

oh.....i know we have Windows 2003....but when i login in FTP i can see UNIX string wroted....but if i have not windows ASP don't run...and ASP run perfectly

Back to Top
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 12:08pm
Originally posted by RAVALON RAVALON wrote:

today, my site was hacked totally....if you try to go on www.pcprimipassi.it you could see web site is hacked and not accessible....

In my FTP i can see many files uploaded into which redirect navigation.....all site in the server was hacked, about 416 sites...
 
System admin are studing this case of hacking.....
 
Is possibible obatin FTP access with some forum bugs ?????
 
There is a Turkish hacking tool that appeared on one of my hosted sites a few months ago.  I now use the hacker tool to test the security of all the hosts I use.  I have found that on 100% (all, every, without exception) of the hosts, the anonymous IUSR_ account has write permissions on all attached drive partitions.  Some individual web site folders (like my own), the administrator of that site has restricted the IUSR account to read-only permission.  But, I was able to plant a test file and delete that file in the C:, C:\WINNT\ or C:\WINDOWS\, SYSTEM32, etc. etc.   I had access to every single other domain on the same physical machine as my own, simply by having that hacker utility in any readable folder on my site.  So, any of the 416 sites could have anonymous FTP enabled to upload the file to a Web accessible folder, or any other site could have some other upload function.  Once the hacker utility is on the machine ANYWHERE, all sites are at the mercy of the hacker.  Hosts I've verified vulnerable and notified are: iPowerWeb, Nevidia, and VitalStream.  Hosting companies assume their systems are secure because they assume the anonymous account has no means or browsing parent folders.  They're wrong.
 
The Access version of WWF is more vulnerable to this kind of attack because the folder in which the Access MDB is placed requires the anonymous account to have create and write permission on the folder itself.  Once the anonymous user has some means of uploading to that folder, they can do anything they want to the forum.  Even if you password protect the MDB, the plain text username and password are going to be stored in your ASP.
 
Frequent backups of the MDB is critical.  Make sure the anonymous IUSR account can write only to the folder holding the MDB (which should have ONLY the MDB) and the forum Uploads folder.  All other folders should allow ONLY read permission to the IUSR account.  The hacker utility doesn't allow the hacker to elevate their identity beyond the anonymous IUSR account, so your main WWF ASP files will be safe WHEN the hacker does it again.
Back to Top
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 2:02pm
Ohhh....and...how can i test if this is the same problem of my server ? how can i try if i could access anonymously ?
 
i tryed to connect with anonymous via FTP but i was refused....in this case do you think IUSR account have write permission ?
Back to Top
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 2:49pm
Originally posted by RAVALON RAVALON wrote:

Ohhh....and...how can i test if this is the same problem of my server ? how can i try if i could access anonymously ?
 
i tryed to connect with anonymous via FTP but i was refused....in this case do you think IUSR account have write permission ?
 
Look for some strange .asp files that you don't recognize as your own.  It's possible that the hacker dropped the hacking utility on your site so that he would have it available to use in case the other admins found it and removed it. 
 
Anonymous FTP has nothing to do with the anonymous IUSR account.  Your host should have some kind of control panel that will let you set permissions on the individual folders for your site.  I suggest you set all folders recursively to "Read-Only" for the IUSR account and then find the forum/Uploads folder and the folder with the Access MDB and set it to "Modify" or "Write".  I suggest you re-check the permissions regularly because the hosting company may reset them by mistake.
Back to Top
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 5:01pm
ok.....but can i change this permission from my PC ? or i have to ask to server support ?? yuo say the best way is check permission .... how can i do this ? could you explain ? or write an example ?
Back to Top
JJLatWebWiz View Drop Down
Groupie
Groupie
Avatar

Joined: 02 March 2005
Location: United States
Status: Offline
Points: 136
Post Options Post Options   Thanks (0) Thanks(0)   Quote JJLatWebWiz Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 6:56pm
It's practically impossible to do from your PC.  File and folder permission don't survive FTP transfers and the FTP service your host runs probably won't allow you to modify permissions.  The only way is through your host's administration control panel or by special request.
 
There is usually a web page that isn't directly associated with your domain, something like "http://ws16.myhostdomain.com:8000" or "http://cp.myhostdomain.com".  They might use vDeck, ensim, plesk, hsphere, cpanel, or their own ASP.NET control panel.  Look for Folder Management or Permission Management.
 
However, I looked at your host's home page and found this frightening statement under their list of features, "PERMISSIONS      READ,WRITE in all folders (777 default)".  You should ask your host if you can set the permissions on individual folders, because you never want the NT equivalent of "777".  If your host won't let you change permissions, consider changing hosts, because they are the hacker's best friend, NOT yours.
Back to Top
ramsey View Drop Down
Newbie
Newbie


Joined: 25 September 2005
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote ramsey Quote  Post ReplyReply Direct Link To This Post Posted: 26 September 2005 at 10:00pm
Originally posted by sfd19 sfd19 wrote:

Qiuck fix:
 
Add

If strUsername = "admin_name" Then

 Set rsCommon = Nothing

 adoCon.Close

 Set adoCon = Nothing

 Response.Redirect "default.asp"

End If
right after this line:

'Read in the users details from the form

strUsername = Trim(Mid(Request.Form("name"), 1, 15))
 
in forgotten_password.asp
 
'admin_name' is of course the name of your admin account.
 
Thank You It worked. and thanks for quick reply.
 
They tried to hack my forum loading files to uploads folder for avatars.
You can solve it by blocking .exe execution from that uploads folder.
 
ramsey
Back to Top
RAVALON View Drop Down
Groupie
Groupie
Avatar

Joined: 31 December 2003
Location: Italy
Status: Offline
Points: 132
Post Options Post Options   Thanks (0) Thanks(0)   Quote RAVALON Quote  Post ReplyReply Direct Link To This Post Posted: 27 September 2005 at 8:36am
Ok JJLatWebWiz....
 
i ask you a last help if you could....
 
Tell me how can i dimostrate my folder have 777 permission, so i can ask to change to my provider with some tests....
 
How you understand what are you saying ?
Back to Top
 Post Reply Post Reply Page  <12345 7>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.