Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Protect yourselves from Turkish Hackers
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Protect yourselves from Turkish Hackers

 Post Reply Post Reply
Author
cyberax View Drop Down
Newbie
Newbie


Joined: 26 September 2005
Location: India
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote cyberax Quote  Post ReplyReply Direct Link To This Post Topic: Protect yourselves from Turkish Hackers
    Posted: 27 September 2005 at 1:52am
Hi Friends,
 
We have been recently hit by the turkish hacker even though we had 7.92 installed on our server.
 
So here are the things you can do to protect yourselves.
 
a) Remove write/modify permission for the Web user on the wwwroot and other subsequent folders. Only allow it on Uploads folder.
 
b) Scan your whole wwwroot folder for files like cyberspy5.asp or hardknock.asp which is a encoded vbscript file which the hacker uses to hijack the site later. I have noticed that they also upload a .txt file with the content of the htm which they can easily copy as default.asp. They will certainly hide it somewhere in your wwwroot subfolders.
 
If you only have FTP access to the site then you would have to download the whole folder and scan it on your hard disk.
 
Look for the string "VBScript.Encode" in the asp files
 
c) If you are using iGallery as your forum's picture gallery then please do install the latest version for the same.
 
d) The have the tendency to create default pages in all the folders on which it gets the write permissions and many times we have to give write permissions to the wwwroot folder as we have scripts which downloads a JavaScript from another PHPBB site to the wwwroot folder which now I am thinking to moving it to some other folder.
 
So you may consider to change the sequence of the default page in IIS to the following order:
  - default.asp
  - default.htm
  - index.asp
  - index.asp
 
And write protect your default.asp on the wwwroot folder.
 
I hope you will find this information useful. Please feel free to comment and if you have similar tips which will help fellow WebWiz Forum owners please do post here.
 
Cheers,
Vijay Bhatter
Back to Top
jeffdaro View Drop Down
Groupie
Groupie


Joined: 15 April 2005
Status: Offline
Points: 171
Post Options Post Options   Thanks (0) Thanks(0)   Quote jeffdaro Quote  Post ReplyReply Direct Link To This Post Posted: 29 September 2005 at 9:55am
Thanks for that concise description.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.