Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 27

Thread: Hackers on my website

  1. #11
    Senior Member
    Join Date
    May 2002
    Posts
    256
    misscoco, with your permission...would you mind me running a few security scans/audits on your website? I can reply back to a private email address with the results. Note, I will NOT alter anything on the website, nor take down the website. As always, no charge
    Sex is like \"Social Security\". You get a little each month, but it\'s not enough to live on.

  2. #12
    Senior Member
    Join Date
    Jul 2002
    Posts
    229
    Hello,

    The most off the top explaination I can give after checking out your server is that they may have cracked your FTP servers user and password and then changed things around. Hopefully you are well aware that you have an FTP server running (at least it is attatched to the domain name you provided) and I assume that you use it to remotely change things on your website.

    If a hacker has access to someones FTP server it is very easy for them to modify your webpage that you are hosting. My recommendation would be to change your username and password and lock it down by limiting the number of connections, disableing annoymous accounts, etc... The FTP server that your running (WS_FTP 1.0.5) IMO Isn't the greatest, try Serv-U instead if your running Windows, it's user friendly and is easy to lock down.

    Also after you have done that run some type of tool that checks for rootkits (tools that hackers use to get into your system, kinda like putting a backdoor entrance to your house). I hope that helps and good luck. I'm sorry this happened to you.
    The real question is not whether peace can be obtained, but whether or not mankind is mature enough for it...

  3. #13
    Senior Member
    Join Date
    May 2002
    Posts
    256
    Also, to chime in on what Radical is saying (good points), I would recommend using a secure password as well and not an easily guessed password (dictionary based). For example, instead of using a password of "password", use the password of "P@ssw0rd" instead. Note, do not use this actual password as it too is easily guessed.

    Best wishes.
    Sex is like \"Social Security\". You get a little each month, but it\'s not enough to live on.

  4. #14
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    A weird one,

    I have done a bit of research, and the vandalised sites seem to be scattered all over the place, with no apparent content similarity or connection; hell, they even hit my hometown's good pub guide? (in the middle of Yorkshire, UK)

    They seem to be a Turkish emigre outfit based in the UK?

    http://s2.phpbbforfree.com/forums/?mforum=ksteam

    misscoco your "communist flag" is, in fact, the Turkish flag

    Turkish intelligence suggests that WaRRiOr is known to them but is not the sharpest tool in the shed. Errrrrrrrr he/she is not in the top 50 I would guess some sort of Bot to collect vulnerable sites then attack a few in each country. Interestingly, the sites all seem to be in NATO/SEATO/EU aligned countries.

    This makes me wonder if it is not an attempt by one group of website defacers to implicate/discredit another. I have heard that there is great rivalry between some of them.

    I guess that you were just unlucky.




  5. #15
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171
    Hi nihil,

    Or is it Sherlock Nihilholmes

    Eg

  6. #16
    Senior Member
    Join Date
    May 2002
    Posts
    256
    DAMN! No kiddin! Someone did their homework
    Sex is like \"Social Security\". You get a little each month, but it\'s not enough to live on.

  7. #17
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    Hi Folks,

    I tried the usual Whois and Traceroute scans, but all I seem to get to is an outfit in NYC, and Traceroute shows a lot of "bogus rDNS", "fraudulent rDNS" and "no rDNS" at the end of the trail.

    I don't believe a word of it

  8. #18
    Senior Member
    Join Date
    May 2002
    Posts
    256
    Hmmm...I see what you are saying nihil
    Im getting
    12 32 ms 33 ms 32 ms o3-2bd1.dfw002ap01.yipes.com [66.7.141.42]
    13 33 ms 31 ms 31 ms 66.7.165.37

    Yipes.com...hmmm..who that be?
    Sex is like \"Social Security\". You get a little each month, but it\'s not enough to live on.

  9. #19
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    Hi Wildred,

    OrgName: Yipes Communications, Inc.
    OrgID: YIPS
    Address: 114 Sansome Street
    City: San Francisco
    StateProv: CA
    PostalCode: 94104
    Country: US

    NetRange: 209.213.192.0 - 209.213.223.255
    CIDR: 209.213.192.0/19
    NetName: YIPES-BLK1
    NetHandle: NET-209-213-192-0-1
    Parent: NET-209-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.YIPES.COM
    NameServer: NS2.YIPES.COM
    NameServer: NS3.YIPES.COM
    Comment:
    RegDate: 2000-04-13
    Updated: 2001-06-29

    TechHandle: IY10-ARIN
    TechName: Yipes Communications, Inc.
    TechPhone: +1-877-788-4662
    TechEmail: [email protected]

    OrgAbuseHandle: ABUSE21-ARIN
    OrgAbuseName: Abuse
    OrgAbusePhone: +1-303-785-4450
    OrgAbuseEmail: [email protected]

    OrgTechHandle: IY10-ARIN
    OrgTechName: Yipes Communications, Inc.
    OrgTechPhone: +1-877-788-4662
    OrgTechEmail: [email protected]

    # ARIN WHOIS database, last updated 2005-08-18 19:10
    # Enter ? for additional hints on searching ARIN's WHOIS database.

    This stuff is all over the place..............proxies, owned or whatever I guess?

    Here is a fraudulent rDNS:

    OrgName: Level 3 Communications, Inc.
    OrgID: LVLT
    Address: 1025 Eldorado Blvd.
    City: Broomfield
    StateProv: CO
    PostalCode: 80021
    Country: US

    ReferralServer: rwhois://rwhois.level3.net:4321

    NetRange: 63.208.0.0 - 63.215.255.255
    CIDR: 63.208.0.0/13
    NetName: LEVEL4-CIDR
    NetHandle: NET-63-208-0-0-1
    Parent: NET-63-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.LEVEL3.NET
    NameServer: NS2.LEVEL3.NET
    Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
    RegDate: 1999-05-28
    Updated: 2001-05-30

    TechHandle: LC-ORG-ARIN
    TechName: level Communications
    TechPhone: +1-877-453-8353
    TechEmail: [email protected]

    OrgAbuseHandle: APL8-ARIN
    OrgAbuseName: Abuse POC LVLT
    OrgAbusePhone: +1-877-453-8353
    OrgAbuseEmail: [email protected]

    OrgTechHandle: ARINC4-ARIN
    OrgTechName: ARIN Contact
    OrgTechPhone: +1-800-436-8489
    OrgTechEmail: [email protected]

    OrgTechHandle: TPL1-ARIN
    OrgTechName: Tech POC LVLT
    OrgTechPhone: +1-877-453-8353
    OrgTechEmail: [email protected]

    It seems to leave London (UK) hit San Francisco, then go to this place in Colorado (?) then go back to San Francisco?

    I am glad I am not paying the taxi fares

  10. #20
    Senior Member
    Join Date
    May 2002
    Posts
    256
    LOL Shoot Im so cross-eyed in tracert that I forgot what the hell the original domain name was ahhh sleep is a good thing....now if only the wife would give me a backrub lol
    Sex is like \"Social Security\". You get a little each month, but it\'s not enough to live on.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •