Skip to main content

site was compromised 2121 Responses

Last post: 3 months, 4 weeks ago | Thread started: Aug 6, 08, 2:47 p.m.

RespondNew TopicDisable Images

  • PIITB

    Hey I got a strange email from google regarding my website:

    "We recently discovered that some of your pages can cause users to be infected with malicious software. We have begun showing a warning page to users who visit these pages by clicking a search result on Google.com."

    After investigating it a little I found some strange script at the bottom of my index page. It seems as though someone hacked my shit. Has this happened to anybody here, what steps should I take?

    Aug 6, 08, 2:47 p.m. – Permalink
  • ukit

    First step, use lots of lubricant

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:48 p.m. – Permalink
  • PIITB

    fucking shit is bothering me. would you change hosts? apparently I am not secure where im at.

    + add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:50 p.m. – Permalink
  • ukit

    I would contact your host first of all, and ask for a refund maybe

    + add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:51 p.m. – Permalink
  • akoni

    change your passwords at least

    • done.PIITB1/4
      oh yeah? well..
      what is it? tell us or it didn't happen
      Meeklo2/4
      hehePIITB3/4
      pics or it didn't happen
      ;oP
      VectorMasked4/4
    next note >+ add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:51 p.m. – Permalink
  • tasty

    I had a dead message board on my site i set up to see how it worked and i left it up. they hacked it, but its all cleared up now.

    change a password, kill the board. password protect.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:51 p.m. – Permalink
  • jonatne

    it could have been done by a bot or some method other than a direct attack.. if the site is high profile then you should hire some sort of security measures.. if it isn't, then delete the script and carefully monitor..
    change ftp login info, ssh login info, etc.. you could even request a new IP from your host

    • thanks, im going to look into all that.PIITB
    + add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:52 p.m. – Permalink
  • bulletfactory

    I built a site not too long ago and got emails from the client saying there was a virus (their virus alert kept going off when they visited the site). I said "No fucking way, it's just xhtml/css. There can't be a virus." Then I noticed a strange script tag at the bottom of the footer (which was included on every page) - After I removed that, no worries. It was just random.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:52 p.m. – Permalink
  • ribit

    We got hacked once through a vulnerability in AW Stats software... You should find out what the cause was before you decide to move..

    • thats just the thing i dont know how it happened or where to start.PIITB1/7
      Depends on what type of hosting... If you don't control add-on software, then I think you have to ask them how it happened..(like all the possible scenarios)ribit2/7
      ..how it could have happened..(like all the possible scenarios)ribit3/7
      and google the code, look for discussions about other people who got hit, etc..ribit4/7
      of course when we got hacked it was a defacement hacking, so they left their name, which helped...ribit5/7
      we then found we were like 2000 on their list of hacks...ribit6/7
      actually heres a story about it:
      http://www.chovy.com…
      ribit7/7
    next note >+ add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:53 p.m. – Permalink
  • bulletfactory

    I would love to see a hacker hack a site, and actually fix some problems. Like leaving a message .........

    "HAXORED BY CLIFF, YOUR SITE IS NOW STANDARDS COMPLIANT, BITCH"

    next note >+ add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 2:54 p.m. – Permalink
  • spendogg

    HAXORED BY JONATNE, YOUR LAPTOP IS NOW ON DA INTERNETZ"

    next note >+ add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 4:10 p.m. – Permalink
  • dog_opus

    This happened on my first blog in 2004, and a friend of mine took care of it for me (I'm pretty weak with the development stuff). There was all sorts of weird script on loads of my pages ('cause it was a blog), and some of them were links (it looked like Javascript, I think). If I remember correctly, he mentioned to me that you should update the scripts on your back end every couple of years.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 5:39 p.m. – Permalink
  • acescence

    is this a static page? are you using some sort of blog software?

    • no blog, I havent even updated the page in a long time.PIITB
    + add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 5:44 p.m. – Permalink
  • acescence

    most people that get hit aren't targeted specifically. i look thru my server logs and see that every day every hour there are 100s of hits from script kiddies looking for specific software they know is vulnerable. they just get a list of random domains and brute force until they find something.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 5:49 p.m. – Permalink
  • dbloc

    This happened last week to one of the sites that we just finished up. check all your code. They added something in. Make sure you change all passwords and possibly host.

    Who is your host? I wonder if it's the same host getting hit.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 8:17 p.m. – Permalink
  • PIITB

    dbloc it was ipowerweb? What host were you using. I tried to contact ipower via email to see if they will give me a refund so I can switch hosts, we'll see if they do.

    • don't tell me this, a client just consolidated all of their domains and sites to manage w/ 1 ipower account.bulletfactory
    + add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 6, 08, 9:24 p.m. – Permalink
  • angelus35

    PHP site? If so, make sure register_globals flag is off. There's all sorts of PHP/MySQL injection attacks that can be made via that setting.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 7, 08, 6:12 a.m. – Permalink
  • utopian2

    WHAT HOST ARE YOU USING?

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 7, 08, 6:14 a.m. – Permalink
  • bulletfactory

    Our SQL servers at the university (where I work) were hit yesterday - what a fucking mess - I'm lucky I'm the designer and not the tech that had to wade through that mess.

    fucking SQL Injection - right after the database was cleaned up, it went in and reinserted the bad code in all the rows again.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 7, 08, 6:19 a.m. – Permalink
  • dbloc

    our client was using verio. so it's probably just random.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 7, 08, 8:51 a.m. – Permalink
  • dbloc

    we did have a database connection....maybe that's it.

    next note >add note

    You must be logged in to add a note. Login now or register for an account.

    Cancel
    Dog-earAug 7, 08, 8:53 a.m. – Permalink

Login or Register to respond to this

Skip to main content