Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 2 12 LastLast
Results 1 to 15 of 23

This is a discussion on rude awakening: spykids Ownz you in the Open Discussion & Chit-chat forum
That was the message that greeted me when I went to look at one of my sites. And it appeared on all the sites on ...

  1. #1
    JPC Addict richardevanslee's Avatar
    Join Date
    Feb 2003
    Location
    Durham, NC
    Posts
    104

    "Spykidz Own You"

    That was the message that greeted me when I went to look at one of my sites. And it appeared on all the sites on that server. Trying to visit Cpanel I got “connection refused.”

    I was able to load Movable Type, everything was there as it should be (and backed up). FTP’d in just fine.

    Only the index pages were mucked with.

    The couple of cgi scripts that I run don’t have any vulnerabilities that I’ve heard of. I don’t share passwords and the like.

    Words of wisdom for someone completely inexperienced with this sort of thing?

  2. #2
    JPC Member
    Join Date
    Oct 2005
    Posts
    4

    Angry rude awakening: spykids Ownz you

    i woke up this morning with the following text on my site.

    it was found in all 'index.*' files on my site, so even in subsites that i had made for friends using 'gallery' as well as my own site which is using Mambo.....

    i found this online:
    http://forum.mamboserver.com/showthread.php?t=26025

    what can be done by JaguarPC?

    i need to update my mambo version, but am not at home at the moment, and cannot even login to my site via the admin.

    has anyone else suffered from this childish behaviour?

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Woo Hoo! That Stefany is hot! I like red-heads...

    Anyway, if it was me, I guess I would contact Tech Support and tell them to take your site down until you've had a chance to check it out. Those turds might have stuck a root kit in there or something. That way you're covered, and 'they' are aware of the situation.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Damn, dude! Did you actually shoot all those girls yourself?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Hrm... Natascha's gallery is still working...

    Must be a Mambo exploit.
    Last edited by Vin DSL; 10-09-2005 at 04:35 AM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    I don't know if you saw this, but 'Viceroy' had some 'emergency' maintenance done to it tonight. I wonder if that had anything to do with it...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  7. #7
    JPC Member
    Join Date
    Oct 2005
    Posts
    4
    vin, how can you see the photo's? i did not even mention a link, only to the mambo site. but anyway, yes i did photograph all the models.

    it must be down again, because none of the sites, even natascha's is working.... what now?

  8. #8
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    I would contact Tech Support here at JaguarPC and have them help you.

    And, Natascha's gallery is still working for me. I'll PM you the URL.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  9. #9
    JPC Member
    Join Date
    Oct 2005
    Posts
    4
    contacted support, are working on it.

    hmm maybe time to change from Mambo..... any suggestions?

  10. #10
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Well, any/all software has security issues. What you have to do is figure out how they cracked your site. The best way to do that is to download your raw log files in cPanel and go over them with a fine toothed comb, so to speak. This usually takes hours and hours, but if you look at your logs long enough, you should be able to figure out what they did. Then, it's just a matter of patching your software.

    At a bare minimum, I would update your software to the latest version and keep up with the upgrades as soon as they come out.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  11. #11
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    I guess work on it has started, Matthew? All I get currently is a "temporarily offline, due to emergency mainenance."
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  12. #12
    JPC Member
    Join Date
    Oct 2005
    Posts
    4
    yeah, have spoken to jaguar and they are working on it, i just got rid of the index.php file that was infected in the root...... looks better than the crack credo

  13. #13
    JPC Addict Daiver's Avatar
    Join Date
    Jul 2005
    Posts
    191
    Link to gallery?

  14. #14
    JPC Addict richardevanslee's Avatar
    Join Date
    Feb 2003
    Location
    Durham, NC
    Posts
    104
    Quote Originally Posted by luchtwafel
    has anyone else suffered from this childish behaviour?
    Me. Same server. I don't run Mambo. Very little php, mostly perl scripts.

    This almost makes me feel good (but not really). I try to be as paranoid, unadventurous as possible so I was pretty baffled what backdoor I could've left open.

    Still can't access my Cpanel after about twelve hours but I trust JaguarPC's tech support folks to get it right so I have no complaint.

    For once I see an advantage to having my fifteen sites on three different servers.

  15. #15
    Loyal Client
    Join Date
    Sep 2001
    Location
    Wichita, KS
    Posts
    1,647

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •