Search (advanced search) | ||||
Use this Search form before posting, asking or make a new thread.
|
05-28-2013, 05:44 PM
Post: #1
|
|||
|
|||
SITE HACK WARNING !! - please read
Hi,
Some of you know of me and the bits I do trying to keep things clean etc. As such, I'm quite happy to say my sites are strong and secure - good passwords, all the usual stuff. Some sites are WP, minimal plugins and themes, all clean as you'd expect. the main sites are hand coded php, so very unlikely... To my shock, more anger... I've just noticed that all my accounts in my reseller account have been hacked.. All the index pages have been tampered with - all timestamped the same day, a few days ago. The code is a crappy content fetch made to look like stats code. visitng the tosser domain redirects to some bots vs browser site. public code viewing and viewing as search engine show no delivered payload... the inserted code is: Code: <?php this points to some tosser here: Code: http://mbrowserstats.com/statH/stat.php whois gives some pointless info, but I will chase it anyway Code: http://whois.domaintools.com/mbrowserstats.com My Host is being slightly less than useless right now, thankfully I don't need their help, just an indication of how they got in you'll see this attack widely reported on the net, starting from feb this year, when the domain was regsitered... checking your source by viewing via browser etc will not help - you need to check for unexpected changes by ftp browsing. |
|||
05-28-2013, 06:05 PM
Post: #2
|
|||
|
|||
RE:
quick update - if you do have this crap on your site...
- Check and clean all index files When cleaning a WP site - Check and clean all index files - in themes, also check and clean footer.php and page.php files it's seems to be from some crappy crawler bot as the patterm is quite precise. Si |
|||
05-28-2013, 06:34 PM
Post: #3
|
|||
|
|||
RE:
The dirty little defacing skid cunts.
I have sent you a PM about some DDOS fun. HMP Wandsworth SUCKS!!
|
|||
05-28-2013, 10:23 PM
Post: #4
|
|||
|
|||
RE:
Thanks for this, I've been noticing some odd crawlers recently on my site as well but I've installed a plugin that helps me in blocking tons of IPs and other things base on rules I base and if they break it they're automatically banned for 1 week and I get notified.
NAAAAAAAAAAAAAAAAAY
If You Find It Useful "+1 REP" It. |
|||
05-28-2013, 10:32 PM
Post: #5
|
|||
|
|||
RE: | |||
05-28-2013, 10:59 PM
Post: #6
|
|||
|
|||
RE:
Thanks for letting us know, I will be reviewing my sites for this from now on.
|
|||
05-29-2013, 01:17 AM
Post: #7
|
|||
|
|||
RE:
Quick update...
Quite odd, it seems the attack may have been linked in some way to filezilla ftp I have on this machine. My machine is clean, - very clean - I check often with a variety of tools. I need this machine daily, too much to risk crappy downloads on.. so I never run windows programs etc that I've 'obtained' on this machine, it's kept in a clean and safe state, saying that, I never download windows stuff only php and embedded source etc. The reason I'm pointing the finger is that all of the accounts - exactly - on the filezilla ftp on this machine are the ones that got hit. There are several others that got totally missed, too many to be chance, as it's an exact match to the 20+ accounts on this software. hmmm... Si |
|||
05-29-2013, 01:55 AM
Post: #8
|
|||
|
|||
RE:
Weird, is there any other commonality between the sites? Might it be the host that got hacked?
|
|||
05-29-2013, 03:25 AM
Post: #9
|
|||
|
|||
RE:
Luckily this did not happen to me.
Thanks for the heads up! |
|||
05-29-2013, 04:14 AM
Post: #10
|
|||
|
|||
RE: | |||