![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Hacking question...hacking gurus step inside.
Ok, check this out.
our computer system is being hacked. It is a password protected area for brokers (mainstream) It appears that somone is hitting the response form and since they are not under a brokers ID, it is trying to send the response to a non existent broker. Am I correct about this, and how should I stop it? Advice anyone? LOG: [23/JUNE/2008 01:30:19] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 [23/JUNE/2008 01:30:22] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 [23/JUNE/2008 01:30:28] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 [23/JUNE/2008 01:30:30] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 [23/JUNE/2008 01:30:34] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 [23/JUNE/2008 01:30:36] Attempt to deliver to unknown recipient </script>, from <[email protected]>, IP address 127.0.0.1 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Too lazy to set a custom title
Join Date: Dec 2004
Posts: 17,513
|
uh that doesn't look like a hack attempt
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2001
Posts: 59,204
|
Well you got his IP address.
127.0.0.1 <--- very evil, used by lots of hackers. Ask your host to block 127.0.0.1 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Your script is attacking you. Uber eleet hacking is going on
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Industry Role:
Join Date: Jul 2006
Location: A magical land
Posts: 15,808
|
There's no place like 127.0.0.1
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Too lazy to set a custom title
Industry Role:
Join Date: May 2003
Location: icq: 71462500 Skype: Jupzchris
Posts: 27,880
|
i cant hack my way out of a paper bag and to me that looks like your computer is doing it
__________________
[email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Would need a link to your form...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
The Dupre Pimp
Join Date: Feb 2008
Location: Koh Samui
Posts: 6,677
|
__________________
Read TOS for signature rules |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
BACON BACON BACON
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
|
hello fbi....i just wanted to say hello
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Thanks guys. So there is a possibility that it is just a bug in the form submission script and not a hack at all? This shit is driving me nuts...every few days the server goes down and we lose the last few days of data.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
bump bump
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
I'd start checking your automated scripts. Anything that is supposed to run on it's own.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Videochat Solutions
Industry Role:
Join Date: Aug 2004
Location: Canada
Posts: 49,098
|
Quote:
You're not being hacked. The IP Address 127.0.0.1 is your local machine that is running this script. (hence the "home" jokes). The messages above are trying to tell you that This Local Machine cannot send the message because the recipient is unknown. (Wrong email address). That's all - no hackers are doing anything nasty to you. Cheers!
__________________
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Do Fun Shit.
Industry Role:
Join Date: Dec 2004
Location: OC
Posts: 13,393
|
__________________
![]() “I have the simplest tastes. I am always satisfied with the best.” -Oscar Wilde |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
you should do a whois on that 127.0.0.1 and see where he lives then go over his place and fuck his ass up good. he fucked with me a few years ago but I found him and beat the living shit out of him with baseball bat. I fucked him up good, he went to the hospital and all.
now this fucker at 192.1683.0.3 is fucking with me, guess I will have to go over his place and straighten out that sonuvabitch too! I am telling you. being a webmaster ain't easy! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Very funny guys...I am very well aware that 127.0.0.1 is the local machine. The problem is that someone or something is triggering it to attempt to send an email every few minutes and in some cases several times a second. This is not a regular user trying to use the form improperly causing an error message, this is either a crazy loop, DOS attack, or attempt to use the form to spam. The attempts are crashing the system.
The way the scripts were designed, the main script(script one) passes info to script two to send the form results to several people...therefore my thoughts on this could be that someone (or a bot they use) are trying to use script number two to send out email to targets so it is untraceable to them, they are using script number two to attempt a DOS attack on someone, or it's just a bug that loops causing the scripting engine to blow up. problem is that I am not familiar enough with ASP (or the windows web server platform). If the script was in PERL or PHP on a linux box for example, the issue would be resolved already. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Anyone recommend somone to go in and fix it (without spending a fortune)? I don't have the time to debug it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Aug 2002
Posts: 5,235
|
problem is that I am not familiar enough with ASP (or the windows web server platform). If the script was in PERL or PHP on a linux box for example, the issue would be resolved already.
Ray, as a suggestion, maybe you should start a thread "Need Windows programmer" and then work from there. may get you better results. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,167
|
Quote:
Your scripts are attacking you man. I told you already. Get a programmer to debug that for you, and stop with hacking theories, they remind me of hollywood movies ![]()
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Apr 2003
Location: Loveland, CO
Posts: 5,526
|
If the scripts were running, unchanged, for a period of time without issue, it could be external. If the scripts were implemented and the problem arose soon after, it's probably a script issue.
Just my $.02 on where to start debugging.
__________________
Your post count means nothing. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
um...yea...I think we acertained that almost right away. But it doesn't mean it's definitely what it is. Thanks for the help though.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
Well, I just took over the problem. I didn't even know it was happening until recently. IT just restored the server every time without saying anything. Aparently, it has been doing it for a long time, like once a month, but it is getting worse and worse, now it crashes twice a day.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2006
Location: Earth
Posts: 30,989
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Industry Role:
Join Date: Jul 2004
Location: New York ICQ#348007554
Posts: 4,212
|
OK well check this out...while this log file explosion is taking place, different websites show in the status bar, and these sites whois back to places like bulgaria etc.
In other words, while you are trying to go to the site, and it is hanging up trying to load, it say's in the status bar "loading www.bulgariasite.com" instead of "loading www.mysite.com". It is a different russian or bulgarian site every time and the url is registered but the site doesn't exist. Also, it is not putting my entire site into a giant iframe, I checked to see if that was the case, so how in the hell could another site name come up? What in the hell would cause that? |
![]() |
![]() ![]() ![]() ![]() ![]() |