Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Turkish Hackers
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Turkish Hackers

 Post Reply Post Reply Page  <12
Author
masterxcom View Drop Down
Newbie
Newbie
Avatar

Joined: 27 December 2005
Location: Turkey
Status: Offline
Points: 2
Post Options Post Options   Thanks (0) Thanks(0)   Quote masterxcom Quote  Post ReplyReply Direct Link To This Post Posted: 27 December 2005 at 8:24pm
i can understand you perfectly because i am from turkey and everyday they try to hack my web site....
let me give you some advises
1)Change your forum database path and name
2)Lots of hacker try to deface your web-site with Css..
They use it in their signiture and if you do not clouse HTML tags use it in their post....
3)Some kind of hackers create mass users and writing mass messages and try to full your database...My suggestion is use security images in register and login users.....

i hope you solve your problem
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 28 December 2005 at 2:14pm
Originally posted by huwnet huwnet wrote:

Originally posted by -boRg- -boRg- wrote:


He also looks for holes in the servers own security, for sites that have not setup permissions securely and have write permissions enabled on public files and folder, this allows a hacker to upload his/her own files to the server to deface of hack the site. Permissions need to be set by your web host, contact them to setup secure permissions for your site.


I have never understood how files can be uploaded to an insecure web server just using the http protocol.

Or does the hacker somehow use the upload script to his advantage?


No hackers don't need to use upload scripts to do this, it's even simpler than that.

Hacking sites by using HTTP to upload files to sites with write and modify permissions enabled is simple.

I'm not going to go into it here as I do not like hacking, but just look on any hacking site.

There are loads of tools to do this, I was even taught how to use hacking tools like this as part of a University course, so that server admins know the security risks and how to prevent them.

The ADO.Stream object, part of ADO on windows servers makes uploading via HTTP even simpler.

Most hackers who do this are usually 14 year olds with to much time on their hands and download simple hacking tools and think it's cool to go around defacing sites, as if it is somthing new.


Edited by -boRg- - 28 December 2005 at 2:17pm
Back to Top
huwnet View Drop Down
Senior Member
Senior Member


Joined: 30 May 2003
Location: England
Status: Offline
Points: 1375
Post Options Post Options   Thanks (0) Thanks(0)   Quote huwnet Quote  Post ReplyReply Direct Link To This Post Posted: 28 December 2005 at 6:04pm
Thanks for the information.

Didn't know things like that where even possible.
Back to Top
Ninjai View Drop Down
Groupie
Groupie


Joined: 29 December 2005
Status: Offline
Points: 45
Post Options Post Options   Thanks (0) Thanks(0)   Quote Ninjai Quote  Post ReplyReply Direct Link To This Post Posted: 30 December 2005 at 11:53am
Wow, didn't realise it was that easy to hack and deface. I've moved and renamed the database and run latest versions but still seems abit of a worry.

Suppose best thing is not to make yourself a target by running old versions and allowing guest post etc..
Back to Top
 Post Reply Post Reply Page  <12

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.