Lost Password?

Go Back   CodeCall Programming Forum > Software Development > Software Security

Software Security Information to inform users on how to protect their personal software / applications. Learn how to protect against software crackers.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-13-2007, 01:10 PM
TcM's Avatar   
TcM TcM is offline
Terminator - I'll be back
 
Join Date: Aug 2006
Location: In a technologic world :p
Posts: 5,748
Rep Power: 47
TcM is a jewel in the roughTcM is a jewel in the roughTcM is a jewel in the rough
Default My Website got hacked!

Well on September 10th my website got hacked. A subfolder contained an index.html saying that this website was hacked from a Turkish '''person''' Thanks God it was just an unused subfolder.

Any ideas on how to increase my websites security?

If this is not the right forum please move it.
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall


Business Directory | Technology Blog | Windows Help
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Sponsored Links
  #2 (permalink)  
Old 09-13-2007, 02:56 PM
c0de's Avatar   
c0de c0de is offline
Learning Programmer
 
Join Date: Sep 2007
Location: NoWay
Posts: 36
Rep Power: 0
c0de is on a distinguished road
Default

Hmm, how do I know turkish people they do not hack web sites if your web site contained any photo, video, or anything what turkish people don't like it, or they hack web sites to tell you what your site has opens..
Try using some meta tags about security, use this, I think this will help you a bit!

HTML Code:
<meta name="security" content="medium" />
In place of medium you can use high or low, but can I view your source for a good answer to your question?
__________________
Missing...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 09-13-2007, 03:59 PM
Jordan's Avatar   
Jordan Jordan is offline
Administrator
 
Join Date: Nov 2005
Location: Hendersonville, NC
Age: 25
Posts: 4,565
Last Blog:
PHP: list()
Rep Power: 50
Jordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud ofJordan has much to be proud of
Send a message via ICQ to Jordan Send a message via AIM to Jordan Send a message via MSN to Jordan
Default

Most hackers are "Script Kiddies" from my experience and most of the time they gain access through a script. Do you have any scripts that allow uploading?
__________________
CodeCall Blog | CodeCall Wiki | Shareware Site | Linux Forum | Write a Blog
Don't hesitate to ask any questions that you have! Check out our ASCII Calculator!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 09-13-2007, 06:40 PM
TcM's Avatar   
TcM TcM is offline
Terminator - I'll be back
 
Join Date: Aug 2006
Location: In a technologic world :p
Posts: 5,748
Rep Power: 47
TcM is a jewel in the roughTcM is a jewel in the roughTcM is a jewel in the rough
Default

@c0de: What do you mean? What are those meta tags supposed to do? And sure you can view the source! Just click View --> Source

@Jordan: Yes I have, but the script removed the extension and renames the uploaded file to a random string, but this one was named as index.html, so I don't know how the heck he did it!

btw the website hacked is FindItGlobally.com - Business Directory and the subfolder www.finditglobally.com/upfile (this now redirects to FindItGlobally.com - Business Directory, the subfolder where the script uploads the files.

Just to let you know, I changed the cPanel password, and made index.html in every subfolder where there is no index.html and now they redirect to FindItGlobally.com - Business Directory
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall


Business Directory | Technology Blog | Windows Help

Last edited by TcM; 09-13-2007 at 06:47 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 09-13-2007, 11:00 PM
TkTech TkTech is offline
CrazyOne
 
Join Date: Jun 2006
Posts: 718
Last Blog:
Having trouble with yo...
Rep Power: 50
TkTech is on a distinguished road
Send a message via MSN to TkTech
Default

Can you give any more details on the >>cracker<< ( God I hate when people misuse the word hacker. Its CRACKER not hacker. )

You'd be surprised what I can dig up with a little info.
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Sponsored Links
  #6 (permalink)  
Old 09-14-2007, 03:55 AM
TcM's Avatar   
TcM TcM is offline
Terminator - I'll be back
 
Join Date: Aug 2006
Location: In a technologic world :p
Posts: 5,748
Rep Power: 47
TcM is a jewel in the roughTcM is a jewel in the roughTcM is a jewel in the rough
Default

Well All I can say is that in his nickname there was something like blalba-IsTaMbUl or something similar (I do not remember the blabla part), the page background was black and it had a big image with the Turkish symbol (the one on their flag) and it was very....uncool (the image) He even had a website the same as his nickname

I can't remember more, because I deleted the index.html.

BTW, to upload there is a cpanel to manage the website, and to upload you have to add a new entry (as this is a business directory) but there are none added. You cannot upload without adding an entry! When I say entry I mean something like this:

FindItGlobally.com - Business Directory >> Framegrip Ltd - Detailed Information

You Have to! So I don't know how the heck he uploaded it. And as I said the file name is renamed.

And sorry for using Hacker.. although I think he is a Script Kiddie (Pawned) <- Dam that!
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall


Business Directory | Technology Blog | Windows Help

Last edited by TcM; 09-14-2007 at 04:00 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 11-07-2007, 09:28 PM
Kaabi's Avatar   
Kaabi Kaabi is offline
Programming God
 
Join Date: Jul 2006
Posts: 884
Rep Power: 13
Kaabi is on a distinguished road
Default

I don't get why when websites get hacked they can't easily get reuploaded.
__________________
Cheap Airsoft Guns

If you are looking for high-quality, yet cheap, airsoft guns, then check out MrAirsoft.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 11-09-2007, 06:36 PM
TcM's Avatar   
TcM TcM is offline
Terminator - I'll be back
 
Join Date: Aug 2006
Location: In a technologic world :p
Posts: 5,748
Rep Power: 47
TcM is a jewel in the roughTcM is a jewel in the roughTcM is a jewel in the rough
Default

Well that's not the answer.. the answer is finding and fixing the security issue! and why should I re upload all my websites because of some n00b, thinking he can PawN?
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall


Business Directory | Technology Blog | Windows Help
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 12-24-2007, 04:31 PM
kresh7 kresh7 is offline
Learning Programmer
 
Join Date: Jun 2007
Posts: 99
Rep Power: 4
kresh7 is on a distinguished road
Default

so dident saw this topic before so hackers use rfi remote file inlclude to put a .php or a .txt now it works with .jpg and .gif too
the hackers find a bug in your page and then the put that php file or some other file into your host the mos use c99.php its a shell that allows me to to anything what i want in your site i can connect to the site with netcat and do more damge to your site
when i hacked i puted into the site a phpmailer and spamed until the web closed an other method is xss cross site scripting withthat way the "hacker" steales your admin cookie and gets access through your site
and other way that i dont know how to explain is rooting
if you wanna protect your site use htaccess or meta taks like someone above sad
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 12-27-2007, 05:52 PM
TcM's Avatar   
TcM TcM is offline
Terminator - I'll be back
 
Join Date: Aug 2006
Location: In a technologic world :p
Posts: 5,748
Rep Power: 47
TcM is a jewel in the roughTcM is a jewel in the roughTcM is a jewel in the rough
Default

I don't know if this cracker use any of those scripts :S I have no idea how he did it!
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum
Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall


Business Directory | Technology Blog | Windows Help
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Sponsored Links
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
How 2 create a website tutorial mysticalone Website Design 3 02-02-2007 06:42 PM
Website Goodies littlefranciscan Website Design 1 01-15-2007 11:14 AM
Website Backlinks TcM Search Engine Optimization 10 01-09-2007 02:02 PM
12 Website Design Decisions Your Business or Organization Will Need to Make Void Website Design 1 07-04-2006 08:42 PM


All times are GMT -5. The time now is 01:21 AM.

Contest Stats

dargueta ........ 93.00000
John ........ 87.50000
Xav ........ 70.00000
MeTh0Dz ........ 20.00000
gaylo565 ........ 18.00000
Johnnyboy ........ 3.00000

Contest Rules

Ads