Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-30-2007, 10:39 AM   #1
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Fucking Hacker Cunts

Some fucker hacked my website and deleted the whole fucking website, fucking hacker scumbags, This is total bullshit, so anybody who has links to my site, it will be back up within 24 hours
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:12 AM   #2
ridikuloz
Confirmed User
 
ridikuloz's Avatar
 
Join Date: Jun 2005
Location: ▓NY▓
Posts: 2,080
ouch.... nice directory :X
__________________
Each persons' level of stupidity makes us different.
ridikuloz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:13 AM   #3
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
If people would secure their shit...

Lets start by setting

Options -Indexes
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:28 AM   #4
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Babaganoosh View Post
If people would secure their shit...

Lets start by setting

Options -Indexes
Ok so please help me out here with security issues as i am a noob at this game and any security help would really be apreciated
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:30 AM   #5
TubeTitans_SusieQ
Confirmed User
 
TubeTitans_SusieQ's Avatar
 
Join Date: May 2007
Location: Sunny Florida
Posts: 3,884
that sucks, hope you get it fixed!
__________________





ICQ: 370399852
TubeTitans_SusieQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:31 AM   #6
fatfoo
ICQ:649699063
 
Industry Role:
Join Date: Mar 2003
Posts: 27,763
yea how do you secure shit?
__________________
Send me an email: [email protected]
fatfoo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:39 AM   #7
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by ADL_SusieQ View Post
that sucks, hope you get it fixed!
Thanks, I do regular backups and so does the server, its just so bloody annoying , and inconvenient
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:42 AM   #8
drocd
Confirmed User
 
Join Date: Aug 2007
Posts: 128
black hackers?
__________________
230-699
drocd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:43 AM   #9
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by drocd View Post
black hackers?
what do you mean by black hackers?
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:44 AM   #10
G-Rotica
Confirmed User
 
Industry Role:
Join Date: Aug 2005
Location: Austin, TX
Posts: 4,258
hackers suck. if you're a hacker reading this, I didn't mean that. please leave my shit alone.
__________________
G-Rotica is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:45 AM   #11
pornpf69
Too lazy to set a custom title
 
pornpf69's Avatar
 
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
1st thing upload and INDEX page to your site!
pornpf69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:46 AM   #12
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by G-Rotica View Post
hackers suck. if you're a hacker reading this, I didn't mean that. please leave my shit alone.

__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:47 AM   #13
Extreme John
Confirmed User
 
Join Date: Apr 2002
Location: Fl
Posts: 1,475
that sucks man hopefully youll get everything up quick.
__________________
Florida Honnies - Extreme John


51299342
Extreme John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:48 AM   #14
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by pornpf69 View Post
1st thing upload and INDEX page to your site!

Thanks im doing that now
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 11:51 AM   #15
Martin3
Confirmed User
 
Join Date: Oct 2005
Location: Houston
Posts: 1,529
Ditch the virtual server and get a decent managed dedicated.
__________________
264-543-302
Martin3 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 12:02 PM   #16
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Martin3 View Post
Ditch the virtual server and get a decent managed dedicated.
wish i could but i cant afford that I have only had the website on the net for just over 4 months and I have only just started making a few pennies out of it, then all this shit happens
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 12:19 PM   #17
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Extreme John View Post
that sucks man hopefully youll get everything up quick.

Thanks, should all be up and running again within 24 hours , I have found all sorts of strange files in my public_hml directory, lol and they changed all the directory and file permissions
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 12:35 PM   #18
inabon
Good Old Fat Webmaster
 
inabon's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Boquete, Panamá
Posts: 967
where are you hosting that site?
__________________
Whoever dies with most toys wins.
inabon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 12:53 PM   #19
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by inabon View Post
where are you hosting that site?
Hi its on hostgator..Why?
__________________

Get FREE website listings on Cryptocoinshops.net

Last edited by halfpint; 08-30-2007 at 12:54 PM..
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 01:37 PM   #20
HairToStay
Confirmed User
 
HairToStay's Avatar
 
Join Date: Oct 2002
Location: Southcoast, Mass.
Posts: 1,521
What was exploited in this "hack"?
HairToStay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 01:41 PM   #21
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by HairToStay View Post
What was exploited in this "hack"?
They deleted the whole website, I have only uploaded the index at the moment, The server host is doing the reinstall as they have the most recent backup of the website
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 01:50 PM   #22
riabanana
Confirmed User
 
Join Date: Jul 2007
Posts: 313
Bad times man...
__________________
Vibrators, dildos, cock rings and all other sex toys? We've got them ALL for you.

http://venustoys.com
riabanana is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 02:41 PM   #23
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Found some pretty weird files in my public html folder

these are some of the names

.zshrc
.canna
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 02:59 PM   #24
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
funny
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 03:03 PM   #25
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by TeenCat View Post
funny

one of them had all this funny chinese writing in them lol
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 03:11 PM   #26
C-Bass
Confirmed User
 
C-Bass's Avatar
 
Join Date: Apr 2003
Location: th3 1nt3Rwebz
Posts: 3,153
You's g0t di h4x0r3d
__________________
"Unhappy with the riches 'cause you're piss poor morally."

Trade traffic? - Highdef Blog
C-Bass is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 03:19 PM   #27
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
[QUOTE=Spotter_03;13011354]You's g0t di h4x0r3d



I cannot fault hostgator they have reinstalled evrey thing and done it real quick, really great support from them
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 04:31 PM   #28
CaptainHowdy
Too lazy to set a custom title
 
CaptainHowdy's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: Happy in the dark.
Posts: 92,999
Quote:
Originally Posted by halfpint View Post
I cannot fault hostgator they have reinstalled evrey thing and done it real quick, really great support from them
Good to know !
__________________
FLASH SALE INSANITY! deal with a 100% Trusted Seller
Buy Traffic Spots on a High-Quality Network

1 Year or Lifetime — That’s Right, Until the Internet Explodes!
CaptainHowdy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 04:57 PM   #29
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Thought i would just say a thankyou to hostgator for their great support and change my sig..and maybe get other peeps to sign up
__________________

Get FREE website listings on Cryptocoinshops.net

Last edited by halfpint; 08-30-2007 at 04:58 PM..
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 05:04 PM   #30
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by halfpint View Post
Thought i would just say a thankyou to hostgator for their great support and change my sig..and maybe get other peeps to sign up
Dude, unless you have some bad cgi scripts you installed then it's totaly your hosting companies falut. The hackers most likely got in because you had a weak password or you have an old version of SSH installed on the server.

Your host should detect the attempts at your password and shut login down and they should have the lastest SSH installed.
__________________
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 05:10 PM   #31
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by sortie View Post
Dude, unless you have some bad cgi scripts you installed then it's totaly your hosting companies falut. The hackers most likely got in because you had a weak password or you have an old version of SSH installed on the server.

Your host should detect the attempts at your password and shut login down and they should have the lastest SSH installed.
I think a lot of it was my fault, I was messing about with some cgi scripts, one which was yours and i had changed some of the directory and file perrmissions, so I guess this made it much more easyier to hack the site

(not your scripts fault btw its was my stupidity i guess)
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 07:23 PM   #32
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by halfpint View Post
I think a lot of it was my fault, I was messing about with some cgi scripts, one which was yours and i had changed some of the directory and file perrmissions, so I guess this made it much more easyier to hack the site

(not your scripts fault btw its was my stupidity i guess)
Damn dude, you never ran the script so it can't be hacked.

Hackers can't do anything with bad file permissions unless they are actually on your server already.

File permissions stop other accounts on your server from writing to your files.
And if your server is partioned to private virtual account that shit don't even matter because nobody can even get a path to your account to even attempt to write.

FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!!

But hey, you will not listen...so good luck.
__________________
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 07:36 PM   #33
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by sortie View Post
Damn dude, you never ran the script so it can't be hacked.

Hackers can't do anything with bad file permissions unless they are actually on your server already.

File permissions stop other accounts on your server from writing to your files.
And if your server is partioned to private virtual account that shit don't even matter because nobody can even get a path to your account to even attempt to write.

FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!!

But hey, you will not listen...so good luck.

Ok i also recieved this from the tech guys "but keep in mind if your scripts have SQL injection or other vulnerabilities this isn't something we can really actively scan for. You'll need to keep any scripts and/or CMS systems you have installed updated to the latest versions"
also I was playing with another script which i did install and ran what I said was it had nothing to do with your script..unless you cant read, I also said that it was most probally my stupidy for leaving the directories/files vunrable
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 07:44 PM   #34
directfiesta
Too lazy to set a custom title
 
directfiesta's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: Punta Cana, DR
Posts: 29,585
Quote:
Originally Posted by halfpint View Post
Ok i also recieved this from the tech guys "but keep in mind if your scripts have SQL injection or other vulnerabilities this isn't something we can really actively scan for. You'll need to keep any scripts and/or CMS systems you have installed updated to the latest versions"
\
They are right.
A lot of open source scripts ( Wordpress,joomla,etc...) have holes that hackers use to either change your front page or delete your site.
Keep your scipts up-to-date and lower as much as possible the permission of your folders.
__________________
I know that Asspimple is stoopid ... As he says, it is a FACT !

But I can't figure out how he can breathe or type , at the same time ....
directfiesta is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 07:48 PM   #35
tony286
lurker
 
tony286's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: atlanta
Posts: 57,021
man that sucks.
tony286 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 07:49 PM   #36
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by directfiesta View Post
They are right.
A lot of open source scripts ( Wordpress,joomla,etc...) have holes that hackers use to either change your front page or delete your site.
Keep your scipts up-to-date and lower as much as possible the permission of your folders.
Thank you. The script which i installed was nothing to do with the cgi tube, it was a topsite script, and as sortie stated i could not install his script as it gave me an internal server error and because i was mesing about with scripts I was changing directory perrmissions and did not put them back so this just makes it all the more easeir for some one to do what they did
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-30-2007, 10:37 PM   #37
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Haha do you want to know what is funny about this, because pornpf69 sugested i upload my index page before the website was reinstalled I got a signup from my index page, nothing big, but it was a signup, suppose it was because the users had nowhere else to go on the website but the index page, so after all this crap it actually turned out not so bad, maybe this is the way to go a one page website.....

Thanks guys for your help
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 12:14 AM   #38
TeenCat
Too lazy to set a koala
 
TeenCat's Avatar
 
Industry Role:
Join Date: Jan 2007
Location: CZ/EU forever!
Posts: 16,139
hey man what about to leave internet and bake some cookies? ;)
__________________

6bot
/ Coming again very soon!
Svit Zlin Radio 24/7!
TeenCat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 07:00 AM   #39
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Quote:
Originally Posted by sortie View Post
Dude, unless you have some bad cgi scripts you installed then it's totaly your hosting companies falut. The hackers most likely got in because you had a weak password or you have an old version of SSH installed on the server.

Your host should detect the attempts at your password and shut login down and they should have the lastest SSH installed.
Clueless. Refrain from giving advices on these matters.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 07:10 AM   #40
drjones
Confirmed User
 
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
Quote:
Originally Posted by sortie View Post
Damn dude, you never ran the script so it can't be hacked.

Hackers can't do anything with bad file permissions unless they are actually on your server already.

File permissions stop other accounts on your server from writing to your files.
And if your server is partioned to private virtual account that shit don't even matter because nobody can even get a path to your account to even attempt to write.

FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!!

But hey, you will not listen...so good luck.
Hackers can do plenty if you are publicly serving world writable directories and files through your webserver. No shell access needed.
__________________
ICQ: 284903372
drjones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 07:12 AM   #41
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally Posted by sortie View Post
Damn dude, you never ran the script so it can't be hacked.

Hackers can't do anything with bad file permissions unless they are actually on your server already.

File permissions stop other accounts on your server from writing to your files.
And if your server is partioned to private virtual account that shit don't even matter because nobody can even get a path to your account to even attempt to write.

FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!!

But hey, you will not listen...so good luck.
Note to self: stay the fuck away from TubeCGI... the guy who made it knows absolutely nothing about computers.
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 08:19 AM   #42
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by Libertine View Post
Note to self: stay the fuck away from TubeCGI... the guy who made it knows absolutely nothing about computers.
Ok, please explain how a hacker who cannot get in thru SSH or a script or a server port can write to any directory.

I would like to know this.

Didn't the wordpress hacks etc... all involve the script accepting data from an html page and then executing it, which is a no-no. They fixed that issue as soon as they realized the mistake.

I'm serious, please explain. I'm not being sarcastic. If you have this information then please share it so people can protect themselves.
__________________
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 08:26 AM   #43
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by drjones View Post
Hackers can do plenty if you are publicly serving world writable directories and files through your webserver. No shell access needed.
Yeah, they can do plenty without shell access but doesn't it mostly involve feeding something to a script that executed it and they gain access that way.

They could flood the old version of SSH and cause integer overflow which allowed them server access without a password.

What have you seen that was different then that?

I mean, if you know then don't keep it a secret and let us all get hacked.
__________________

Last edited by sortie; 08-31-2007 at 08:28 AM..
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 09:07 AM   #44
sortie
Confirmed User
 
sortie's Avatar
 
Industry Role:
Join Date: Mar 2007
Posts: 7,771
Quote:
Originally Posted by sortie View Post
FACT: If you have to chmod to keep others from writing to your files then your hosting is SHIT!!

http://resources.bravenet.com/articl...php_script s/


Have a good day.
__________________
sortie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 10:04 AM   #45
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Hi just an update on what has happened The tech guys sent me this

This appears to be telnet script which allows the user to remove files. I have disabled these scripts from the cgi-bin and blocked the connecting IP. I am also showing that this user connected to the toplist scripts,
If this script is not being used, I would recommend removing the toplist scripts from your account.

I had an idea it was this stupid topsite script that caused it, the name of the toplist is "Best Top List" so stay away from it it is bad news
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 10:13 AM   #46
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
BTW The IP address is showing up from Mauritius
Africa but whois is to know that this is their real IP but glad they sorted it
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 11:05 AM   #47
alby_persignup
Confirmed User
 
Join Date: May 2007
Posts: 3,119
that shit hurts! sucks
__________________
OnProbation Links Directory | OnProbation Design Services | OnProbation Cash
alby_persignup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 11:27 AM   #48
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally Posted by sortie View Post
Ok, please explain how a hacker who cannot get in thru SSH or a script or a server port can write to any directory.

I would like to know this.

Didn't the wordpress hacks etc... all involve the script accepting data from an html page and then executing it, which is a no-no. They fixed that issue as soon as they realized the mistake.

I'm serious, please explain. I'm not being sarcastic. If you have this information then please share it so people can protect themselves.
It's all about maximum security.

The reason you always set permissions as low as possible is so that, for example, you have some added security against badly written scripts.

Every programmer knows, or should know, that mistakes can and will slip through. By using security at every level, you can prevent those mistakes from becoming disasters.

You use low permissions for the same reason you don't keep unencrypted user passwords in your database: to make sure that if someone manages to slip through, he can do as little as possible.
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 11:33 AM   #49
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Quote:
Originally Posted by sortie View Post
From your own damn link:

Quote:
Q. So with Chmod 777 not being a security problem, why should I use other chmod settings?
A. Because we all take a maximum security view point and keeping chmod settings lower than 777 will simply provide additional security for each individual file. This is part of a maximum security philosophy.
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-31-2007, 11:40 AM   #50
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by alby_persignup View Post
that shit hurts! sucks
Yeah its a pain in the arse but most of it was my own fault for installing a crappy script in the first place, it has taught me not to use free scripts and from what i saw of the script that was deleteing my pages it was actually looking for files, it had commands like this

'find suid files'
'find config* files'
'find all writable files'
'find all writable directories'
'find all service.pwd files'
'show opened ports'

and a load more, Im not gonna post them all here

Pretty mad but I have learned a good lesson from this, like i would never get hacked, its always somebody else, and anyway why would someone hack a small site like mine so just watch what scripts you install
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.