|
||||||
| Software Security Information to inform users on how to protect their personal software / applications. Learn how to protect against software crackers. |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Display Modes |
|
|||||
|
Well on September 10th my website got hacked. A subfolder contained an index.html saying that this website was hacked from a Turkish '''person''' Thanks God it was just an unused subfolder.
Any ideas on how to increase my websites security? If this is not the right forum please move it.
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall ![]() Business Directory | Technology Blog | Windows Help |
| Sponsored Links |
|
|
|
|||||
|
Most hackers are "Script Kiddies" from my experience and most of the time they gain access through a script. Do you have any scripts that allow uploading?
__________________
CodeCall Blog | CodeCall Wiki | Shareware Site | Linux Forum | Write a Blog Don't hesitate to ask any questions that you have! Check out our ASCII Calculator! |
|
|||||
|
@c0de: What do you mean? What are those meta tags supposed to do? And sure you can view the source! Just click View --> Source
![]() @Jordan: Yes I have, but the script removed the extension and renames the uploaded file to a random string, but this one was named as index.html, so I don't know how the heck he did it! btw the website hacked is FindItGlobally.com - Business Directory and the subfolder www.finditglobally.com/upfile (this now redirects to FindItGlobally.com - Business Directory, the subfolder where the script uploads the files. Just to let you know, I changed the cPanel password, and made index.html in every subfolder where there is no index.html and now they redirect to FindItGlobally.com - Business Directory
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall ![]() Business Directory | Technology Blog | Windows Help Last edited by TcM; 09-13-2007 at 06:47 PM. |
|
|||
|
Can you give any more details on the >>cracker<< ( God I hate when people misuse the word hacker. Its CRACKER not hacker. )
You'd be surprised what I can dig up with a little info.
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall |
| Sponsored Links |
|
|
|
|||||
|
Well All I can say is that in his nickname there was something like blalba-IsTaMbUl or something similar (I do not remember the blabla part), the page background was black and it had a big image with the Turkish symbol (the one on their flag) and it was very....uncool (the image) He even had a website the same as his nickname
I can't remember more, because I deleted the index.html. BTW, to upload there is a cpanel to manage the website, and to upload you have to add a new entry (as this is a business directory) but there are none added. You cannot upload without adding an entry! When I say entry I mean something like this: FindItGlobally.com - Business Directory >> Framegrip Ltd - Detailed Information You Have to! So I don't know how the heck he uploaded it. And as I said the file name is renamed. And sorry for using Hacker.. although I think he is a Script Kiddie (Pawned) <- Dam that!
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall ![]() Business Directory | Technology Blog | Windows Help Last edited by TcM; 09-14-2007 at 04:00 AM. |
|
|||||
|
I don't get why when websites get hacked they can't easily get reuploaded.
__________________
Cheap Airsoft Guns If you are looking for high-quality, yet cheap, airsoft guns, then check out MrAirsoft.com |
|
|||||
|
Well that's not the answer.. the answer is finding and fixing the security issue! and why should I re upload all my websites because of some n00b, thinking he can PawN?
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall ![]() Business Directory | Technology Blog | Windows Help |
|
|||
|
so dident saw this topic before so hackers use rfi remote file inlclude to put a .php or a .txt now it works with .jpg and .gif too
the hackers find a bug in your page and then the put that php file or some other file into your host the mos use c99.php its a shell that allows me to to anything what i want in your site i can connect to the site with netcat and do more damge to your site when i hacked i puted into the site a phpmailer and spamed until the web closed an other method is xss cross site scripting withthat way the "hacker" steales your admin cookie and gets access through your site and other way that i dont know how to explain is rooting if you wanna protect your site use htaccess or meta taks like someone above sad ![]() |
|
|||||
|
I don't know if this cracker use any of those scripts :S I have no idea how he did it!
__________________
CodeCall Blog | CodeCall Wiki | Shareware | Linux Forum Chat with other CodeCall members on IRC; connect to irc.codecall.net and join #codecall ![]() Business Directory | Technology Blog | Windows Help |
| Sponsored Links |
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How 2 create a website tutorial | mysticalone | Website Design | 3 | 02-02-2007 06:42 PM |
| Website Goodies | littlefranciscan | Website Design | 1 | 01-15-2007 11:14 AM |
| Website Backlinks | TcM | Search Engine Optimization | 10 | 01-09-2007 02:02 PM |
| 12 Website Design Decisions Your Business or Organization Will Need to Make | Void | Website Design | 1 | 07-04-2006 08:42 PM |