Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 09:58:44 AM

Pages: [1]   Go Down
  Print  
Author Topic: Site Hacked  (Read 831 times)
whats2
Newbie
*
Offline Offline

Posts: 2


« on: July 12, 2009, 03:29:24 PM »

My site has been hacked as well - Sedna -
first I discovered folders with hundreds of porno urls
then I discovered the javascript code - added just at the end of the head on html pages and at the bottom of some php pages
seemed to get almost every index.xx or home.xx page
after deleting it comes back within a day or two

Still battling this

also know that the JS code is disguised - there are letters added - which then are taken out as code is read making it look like something else

Any ideas how to fix???

signed - tearing my hair out!
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #1 on: July 13, 2009, 06:01:03 AM »

Sounds like you have a hole somewhere in your account where the bad guys keep coming in.  I would suggest that you follow the suggestions here first:

http://wiki.lunarpages.com/Web_Site_Security_Breaches

Also be sure to check folder permissions, to make sure nothings is writable by the general public, change your passwords, also be sure to check files like your .htaccess to make sure no code that shouldn't be in there is in there. 
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
fretnmore
Grandma Looney
Über Jedi
*****
Offline Offline

Posts: 2863



WWW
« Reply #2 on: July 15, 2009, 11:58:14 AM »

My site has been hacked also. I looked at that page Mitch. It basically says to change your passwords and clean up the site. That isn't a whole lot of help when we can't tell where this attack is coming from or how we can permanently stop it.  My error logs show that it started on the 15th ( at this point I'm not sure what today's date is <sigh> )
Logged

Life is not measured by the number of breaths we take, but by the moments that take our breath away.
----------------------------------------------------------
Tri-Wolf Studios
Lunarpages Web Hosting
Lunarpages Forums
Lunarpages Affiliate Program
fretnmore
Grandma Looney
Über Jedi
*****
Offline Offline

Posts: 2863



WWW
« Reply #3 on: July 15, 2009, 12:48:39 PM »

I have an IP address of 67.195.113.227  which shows the first error logs for my hacked sites. This is in Sunnyvale, CA. If this isn't from someone at LP, then I think this is my hacker.

And he/she seems to be trying to access all of this right now. Meaning NOW, as I am typing.
« Last Edit: July 15, 2009, 01:08:35 PM by fretnmore » Logged

Life is not measured by the number of breaths we take, but by the moments that take our breath away.
----------------------------------------------------------
Tri-Wolf Studios
Lunarpages Web Hosting
Lunarpages Forums
Lunarpages Affiliate Program
bryantrv
Guest
« Reply #4 on: July 15, 2009, 01:34:06 PM »

That's the Yahoo crawler.
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #5 on: July 15, 2009, 01:51:27 PM »

Might also check your file/folder permissions:

http://wiki.lunarpages.com/Chmod_-_Changing_File_and_Folder_Permissions

fretnmore, I do not think it is a fair thing to say that Lunarpages does nothing to help, as the web site security breaches article is a great reference point for clients to learn from.  Also, as many forum regulars know here, if you need any further documentation, help or anything else under the sun and ask me, I will usually bend over backwards in order to provide it.   Very Happy We can help persuade users to keep themselves secure, and we can provide you with the tools and articles to do so - however we can not monitor every account to make sure your account is secure or not.  Users also need to take the responsibility to make sure there are no security holes on their hosting site, that they are using the latest/most up to date versions of any script or service out there, and that they do not infect themselves via their own computer.  

What we do here is work together with our clients to help.  These forums are here as a collective resource for customers to come together and help with exactly this type of issue.  We are all here to help and learn from each other.   hug me
« Last Edit: July 15, 2009, 01:53:18 PM by Mitch » Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #6 on: July 15, 2009, 02:12:04 PM »

Looking into your issue at hand, you may try blocking suspicious IP addresses.  Here is how you can do that via the .htaccess files:

http://wiki.lunarpages.com/Allow_and_Deny_by_IP_Address

and here is how you create a .htaccess file:

http://wiki.lunarpages.com/Create_htaccess

Hope that helps!
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
fretnmore
Grandma Looney
Über Jedi
*****
Offline Offline

Posts: 2863



WWW
« Reply #7 on: July 15, 2009, 03:25:11 PM »

Thanks Brant. I had no idea that was the crawler. It's following links from somewhere on the site that I didn't put there and that is why it is getting the errors. Great, now in addition to Google, Yahoo will be calling it an attack site.

Mitch, I did NOT say that Lunarpages does nothing to help. I summarized the page you sent us to - basically it said to change your password and clean up your files.  That helps to fix the current existing problem. It doesn't help figure out how to keep it from happening again. As you know this the second time I have dealt with this in just a little over a month.

All of my scripts are up to date. At least they were as of the middle of June when I finally got the last hack cleaned up. My computer is clean, so how are these idiots getting into our accounts? I haven't a clue! I wasn't trying to be nasty or upset you, I just want to find out how to stop this from happening over and over and over again.
Logged

Life is not measured by the number of breaths we take, but by the moments that take our breath away.
----------------------------------------------------------
Tri-Wolf Studios
Lunarpages Web Hosting
Lunarpages Forums
Lunarpages Affiliate Program
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #8 on: July 16, 2009, 05:53:51 AM »

Fretnmore, please give us more information about your actual problem, and I bet somebody can suggest a few more suggestions for you.  Let us know how exactly it appears on the page (like is it hidden in JavaScript, is it an iframe, just a series of links, ect). 
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: