Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-25-2016, 01:58 PM   #1
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
I have a website that keeps on getting hacked...

Custom made script, PHP. Host doesn't want to help.

Suggestions?
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:06 PM   #2
BigFurry
Confirmed User
 
BigFurry's Avatar
 
Industry Role:
Join Date: Nov 2003
Posts: 1,558
Step 1. Get a good PHP coder to look at the script.

Step 2. Get an actual expert to do a security audit.

If you have no money to spend, there are some tips here:
appsec - How to perform a security audit for a PHP application? - Information Security Stack Exchange
BigFurry is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:07 PM   #3
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Host is telling me to go here.

https://sucuri.net

I don't want to pay a monthly fee for their firewall.
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:12 PM   #4
roxpoxy
Confirmed User
 
roxpoxy's Avatar
 
Industry Role:
Join Date: Jan 2015
Posts: 93
sucuri.net is a good start.

does your script use a database? have an admin area with elevated privledges?
allow uploads of images or posting of text?

if you can, scan all files for "base64_decode(" & other common tale tale signs of compromise. "can't remember off the top of my head but a quick google search should point you in the right direction".
__________________
roxpoxy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:13 PM   #5
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Quote:
Originally Posted by roxpoxy View Post
sucuri.net is a good start.

does your script use a database? have an admin area with elevated privledges?
allow uploads of images or posting of text?

if you can, scan all files for "base64_decode(" & other common tale tale signs of compromise. "can't remember off the top of my head but a quick google search should point you in the right direction".
Yes, it does, but I don't update the website anymore.

I am afraid I am not that technical to do the simplest of programming.
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:15 PM   #6
Sly
Let's do some business!
 
Sly's Avatar
 
Industry Role:
Join Date: Sep 2004
Location: Austin, TX
Posts: 31,323
Custom scripts often have security issues. Sometimes from laziness, sometimes because the coder simply didn't know better. Odds are your script is also on the older side, meaning no updates in years, making matters even worse.

If you care about your site, spend the money to get it patched up. Otherwise there is not much that can be done.
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted

Windows VPS now available
Great for TSS, Nifty Stats, remote work, virtual assistants, etc.
Click here for more details.
Sly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:17 PM   #7
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Quote:
Originally Posted by Sly View Post
Custom scripts often have security issues. Sometimes from laziness, sometimes because the coder simply didn't know better. Odds are your script is also on the older side, meaning no updates in years, making matters even worse.

If you care about your site, spend the money to get it patched up. Otherwise there is not much that can be done.
Yes, that's what I am looking to do. The site doesn't bring in a whole lot of money, but it's getting hacked WEEKLY. LOL
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:25 PM   #8
BigFurry
Confirmed User
 
BigFurry's Avatar
 
Industry Role:
Join Date: Nov 2003
Posts: 1,558
Yeah I guess if it's possible to disable all user input (forms, uploads), and make the site "read only", that can be a solution. :p

Unless you have some bad file in your system already. :p
BigFurry is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:34 PM   #9
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Quote:
Originally Posted by BigFurry View Post
Yeah I guess if it's possible to disable all user input (forms, uploads), and make the site "read only", that can be a solution. :p

Unless you have some bad file in your system already. :p
So, if I remove all the malware, can I then make it read only and the website will be safe?
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:45 PM   #10
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by FreeHugeMovies View Post
So, if I remove all the malware, can I then make it read only and the website will be safe?
If you dont plan to update site anymore, you could simply convert all content to HTML format and delete anything in PHP.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2016, 02:58 PM   #11
BigFurry
Confirmed User
 
BigFurry's Avatar
 
Industry Role:
Join Date: Nov 2003
Posts: 1,558
Quote:
Originally Posted by FreeHugeMovies View Post
Host is telling me to go here.

https://sucuri.net

I don't want to pay a monthly fee for their firewall.
They could have meant this tool:
https://sitecheck.sucuri.net/

Quote:
Originally Posted by FreeHugeMovies View Post
So, if I remove all the malware, can I then make it read only and the website will be safe?
Well your chances would definitely improve. As roxpoxy said, many breaches are done through Forms and Uploads.

But I guess it's also not impossible that some PHP scripts get hacked just by using simple URL parameters, if they're done really badly. It's not my expertise, just guessing really.

Quote:
Originally Posted by KlenTelaris View Post
If you dont plan to update site anymore, you could simply convert all content to HTML format and delete anything in PHP.
That would work :-)
BigFurry is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 07:14 AM   #12
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Any of you fuckers want to help and get paid for your time? =]

LMK
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 12:18 PM   #13
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
Ask your host to change all the permissions they can to read only any decent managed host should have at least 1 tech with coding skills that can do this for you.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 12:32 PM   #14
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,223
Quote:
Originally Posted by sandman! View Post
Ask your host to change all the permissions they can to read only any decent managed host should have at least 1 tech with coding skills that can do this for you.
I use Filezilla to do that, is that as good as any other way to change permissions or is there another way that I should do it to be safer?
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 12:39 PM   #15
NatalieK
Natalie K
 
NatalieK's Avatar
 
Industry Role:
Join Date: Apr 2010
Location: Spain
Posts: 19,414
Quote:
Originally Posted by Colmike7 View Post
I use Filezilla to do that, is that as good as any other way to change permissions or is there another way that I should do it to be safer?
this
__________________
My official site Custom vids Make money & get into the businessFirst time girls
Skype: GspotProductions - "Converting traffic into income since 2005"
NatalieK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 12:53 PM   #16
FreeHugeMovies
Too lazy to set a custom title
 
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
Everything changed to read only. Let's see if I get fucked in a week or two!
FreeHugeMovies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2016, 01:16 PM   #17
TrafficRush
See My SIG!
 
TrafficRush's Avatar
 
Industry Role:
Join Date: Dec 2003
Location: Sunny Paradise
Posts: 2,099
contact WOJ he can help! or quantox
__________________
INTRALINK DSP | SIGNUP TO MAKE BANK NOW
Skype: Traffic-RushHour | ICQ: 467617514
TrafficRush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-27-2016, 06:57 AM   #18
celandina
Too lazy to set a custom title
 
Industry Role:
Join Date: Jun 2006
Posts: 11,436
About to launch a new site, just marking this thread in case I run into the same issues.
celandina is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-27-2016, 08:44 AM   #19
MrBeavis
Confirmed User
 
MrBeavis's Avatar
 
Industry Role:
Join Date: Nov 2015
Location: The Netherlands
Posts: 67
Wordpress website?
MrBeavis is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-27-2016, 08:51 AM   #20
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
contact woj, and get your php code updated and look for user input sanitization.
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-27-2016, 09:10 AM   #21
NatalieK
Natalie K
 
NatalieK's Avatar
 
Industry Role:
Join Date: Apr 2010
Location: Spain
Posts: 19,414
Quote:
Originally Posted by freecartoonporn View Post
contact woj, and get your php code updated and look for user input sanitization.
woj is fantastic for "getting the job done" and "great service"
__________________
My official site Custom vids Make money & get into the businessFirst time girls
Skype: GspotProductions - "Converting traffic into income since 2005"
NatalieK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
host, php, script, suggestions, custom, website, hacked



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.