![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
I have a website that keeps on getting hacked...
Custom made script, PHP. Host doesn't want to help.
Suggestions? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Nov 2003
Posts: 1,558
|
Step 1. Get a good PHP coder to look at the script.
Step 2. Get an actual expert to do a security audit. If you have no money to spend, there are some tips here: appsec - How to perform a security audit for a PHP application? - Information Security Stack Exchange |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Host is telling me to go here.
https://sucuri.net I don't want to pay a monthly fee for their firewall. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Jan 2015
Posts: 93
|
sucuri.net is a good start.
does your script use a database? have an admin area with elevated privledges? allow uploads of images or posting of text? if you can, scan all files for "base64_decode(" & other common tale tale signs of compromise. "can't remember off the top of my head but a quick google search should point you in the right direction".
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 | |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Quote:
I am afraid I am not that technical to do the simplest of programming. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Let's do some business!
Industry Role:
Join Date: Sep 2004
Location: Austin, TX
Posts: 31,323
|
Custom scripts often have security issues. Sometimes from laziness, sometimes because the coder simply didn't know better. Odds are your script is also on the older side, meaning no updates in years, making matters even worse.
If you care about your site, spend the money to get it patched up. Otherwise there is not much that can be done.
__________________
Vacares - Web Hosting, Domains, O365, Security & More - Paxum and BTC Accepted Windows VPS now available Great for TSS, Nifty Stats, remote work, virtual assistants, etc. Click here for more details. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Nov 2003
Posts: 1,558
|
Yeah I guess if it's possible to disable all user input (forms, uploads), and make the site "read only", that can be a solution. :p
Unless you have some bad file in your system already. :p |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
So, if I remove all the malware, can I then make it read only and the website will be safe?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | ||
Confirmed User
Industry Role:
Join Date: Nov 2003
Posts: 1,558
|
Quote:
https://sitecheck.sucuri.net/ Quote:
But I guess it's also not impossible that some PHP scripts get hacked just by using simple URL parameters, if they're done really badly. It's not my expertise, just guessing really. That would work :-) |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Any of you fuckers want to help and get paid for your time? =]
LMK |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
Ask your host to change all the permissions they can to read only any decent managed host should have at least 1 tech with coding skills that can do this for you.
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
(>^_^)b
Industry Role:
Join Date: Dec 2011
Posts: 7,223
|
I use Filezilla to do that, is that as good as any other way to change permissions or is there another way that I should do it to be safer?
__________________
![]() I've referred over $1.7mil in spending this past year, you should join in. ![]() ![]() I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years.. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Natalie K
Industry Role:
Join Date: Apr 2010
Location: Spain
Posts: 19,408
|
Quote:
![]()
__________________
My official site ![]() ![]() ![]() Skype: GspotProductions - "Converting traffic into income since 2005" |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Too lazy to set a custom title
Join Date: Dec 2001
Location: Charlotte, NC
Posts: 14,137
|
Everything changed to read only. Let's see if I get fucked in a week or two!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
See My SIG!
Industry Role:
Join Date: Dec 2003
Location: Sunny Paradise
Posts: 2,099
|
contact WOJ he can help! or quantox
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Too lazy to set a custom title
Industry Role:
Join Date: Jun 2006
Posts: 11,436
|
About to launch a new site, just marking this thread in case I run into the same issues.
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Industry Role:
Join Date: Nov 2015
Location: The Netherlands
Posts: 67
|
Wordpress website?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
|
contact woj, and get your php code updated and look for user input sanitization.
__________________
SSD Cloud Server, VPS Server, Simple Cloud Hosting | DigitalOcean
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
Natalie K
Industry Role:
Join Date: Apr 2010
Location: Spain
Posts: 19,408
|
Quote:
![]()
__________________
My official site ![]() ![]() ![]() Skype: GspotProductions - "Converting traffic into income since 2005" |
|
![]() |
![]() ![]() ![]() ![]() ![]() |