GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   server hack? (https://gfy.com/showthread.php?t=386559)

emmanuelle 11-10-2004 04:51 PM

server hack?
 
My friend just had a bunch of his index pages replaced with
"SPYKIDS .. irc.chatplus.com.br #spykids.. enjoy "


Anybody know who's behind this stuff and how they tend to get in?

BIGTYMER 11-10-2004 05:00 PM

They get in via an exploit of some sort. You need to harden and keep your box patched and updated.

Alky 11-10-2004 05:02 PM

Quote:

Originally posted by Kingpins
They get in via an exploit of some sort. You need to harden and keep your box patched and updated.
good advice :1orglaugh

NetRodent 11-10-2004 05:02 PM

Why not ask the people on the irc channel #spykids on the server irc.chatplus.com.br.

Ad3pt 11-10-2004 05:04 PM

Quote:

Originally posted by emmanuelle
My friend just had a bunch of his index pages replaced with
"SPYKIDS .. irc.chatplus.com.br #spykids.. enjoy "


Anybody know who's behind this stuff and how they tend to get in?

server spec's?

BIGTYMER 11-10-2004 05:04 PM

Quote:

Originally posted by Alky
good advice :1orglaugh
And you've got better?

Ad3pt 11-10-2004 05:05 PM

Quote:

Originally posted by Kingpins
They get in via an exploit of some sort. You need to harden and keep your box patched and updated.
how do you know this to be the case?

Dirty F 11-10-2004 05:05 PM

Quote:

Originally posted by emmanuelle


Anybody know who's behind this stuff and how they tend to get in?

Just a wild guess but maybe these guys:

SPYKIDS .. irc.chatplus.com.br

I did some research.

BIGTYMER 11-10-2004 05:07 PM

Quote:

Originally posted by Ad3pt
how do you know this to be the case?
How else would they get in? Did they login via ftp with his u/p? I hight doubt it. And its showing an IRC page and IRC is know for its carding, hacking kiddies.

Ad3pt 11-10-2004 05:11 PM

Quote:

Originally posted by Kingpins
How else would they get in? Did they login via ftp with his u/p? I hight doubt it. And its showing an IRC page and IRC is know for its carding, hacking kiddies.
If they have the ftp u/p it's not an exploit.

On the other hand, if their local workstation is owned by a trojan/keylogger that would be an exploit.

Only point Im trying to make is that having this guy jump to conclusions isn't going to give him the info he needs.

Dirty D 11-10-2004 05:12 PM

It looks like someone got root access to the server.

There are many exploits to get root access.

Here are some tools to check for and fix rootkits

http://www.chkrootkit.org


My advice: :2 cents:
Eliminate any backdoors (rootkit)
Restore the domains
Change all user and root passwords
Verify linux and apache are up to date.

BIGTYMER 11-10-2004 05:15 PM

Quote:

Originally posted by Ad3pt
If they have the ftp u/p it's not an exploit.

On the other hand, if their local workstation is owned by a trojan/keylogger that would be an exploit.

Only point Im trying to make is that having this guy jump to conclusions isn't going to give him the info he needs.

Yes, but the chances are greater that they got in via an exploit.

erehwon 11-10-2004 05:19 PM

Quote:

Originally posted by emmanuelle
My friend just had a bunch of his index pages replaced with
"SPYKIDS .. irc.chatplus.com.br #spykids.. enjoy "


Anybody know who's behind this stuff and how they tend to get in?

It sounds like a run of the mill defacement, your friend probably didn't patch something they should have.

The hackers likely went to a database like Packetstorm and found something to break into the server.

Have your friend drop these guys, http://www.ibouncer.com a line, to lock things down :thumbsup

V_RocKs 11-10-2004 05:22 PM

What domains were effected?


All times are GMT -7. The time now is 04:55 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123