Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 12 of 12

This is a discussion on Hacker keeps changing our index.html page in the VPS & Dedicated forum
Hi, I have secured my VPS very well, but I do not know how Hacker can change all the indexes for my clients at same ...

  1. #1
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196

    Hacker keeps changing our index.html page

    Hi,
    I have secured my VPS very well, but I do not know how Hacker can change all the indexes for my clients at same time !!

    I searched to see if any file the haker created is hidden on the VPS, however, no luck. Any suggestions on what or where to look to fix this??
    Is there any special script or program can be install to stop this kind of thing?
    My site:
    SMS

  2. #2
    JPC Dream Team
    Join Date
    May 2007
    Location
    JPC
    Posts
    635
    You can open a support ticket if you already have not and get the basic security hardening measures performed on your VPS which includes APF Firewall and BFD Brute Force Detection Software installation among other things, You also need to follow guidelines in the following link to ensure that you have secured your accounts properly.

    http://www.jaguarpc.com/support/kbase/731.html
    Jawad A.
    JaguarPC
    Site Links:
    Knowledge Base | Network Status

  3. #3
    Loyal Client thisisit3's Avatar
    Join Date
    Mar 2007
    Posts
    642
    A very powerful hack system has been going around for the past few years and uses FTP passwords stolen from client machines (Windoze mainly) so the actual server was never compromised.

    If the attacker has been adding iframe tags in your index files then its probably this kind of attack and the simple solution is to disable the ftp server and go reset every single password on the server+clients. Once done you may re-enable your ftp server.

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by rashad View Post
    Hi,
    I have secured my VPS very well, but I do not know how Hacker can change all the indexes for my clients at same time !!

    I searched to see if any file the haker created is hidden on the VPS, however, no luck. Any suggestions on what or where to look to fix this??
    Is there any special script or program can be install to stop this kind of thing?
    Anybody running Joomla!?!?

    http://www.zone-h.org/index.php?opti...4981&Itemid=92

    Most of the recently reported defacements have been on Linux systems running Joomla - hackers love it!

    Once they get in, they upload a root kit of sorts...

    EDIT

    BTW, if you visit Zone-H (above) look at the number of attacks on Linux vs BSD (top left sidebar)...
    Last edited by Vin DSL; 09-07-2008 at 10:37 AM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    I'll throw in my 2 cents in saying that this is either an FTP attack (as thisisit suggests) or a script-exploit attack. If you are running any scripts (such as CMSes, blogs, discussion forums, etc.) check that you are running the newest version of the application and of any plugins you might be using. Very often the attackers go after bugs in these common programs to gain access to your system.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  6. #6
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196
    Quote Originally Posted by JPC-Howard View Post
    You can open a support ticket if you already have not and get the basic security hardening measures performed on your VPS which includes APF Firewall and BFD Brute Force Detection Software installation among other things, You also need to follow guidelines in the following link to ensure that you have secured your accounts properly.

    http://www.jaguarpc.com/support/kbase/731.html
    JPC Dream Team installed all that on my VPS, also I hired a security company, but still the Hacker having fun !!
    My site:
    SMS

  7. #7
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196
    Quote Originally Posted by thisisit3 View Post
    A very powerful hack system has been going around for the past few years and uses FTP passwords stolen from client machines (Windoze mainly) so the actual server was never compromised.

    If the attacker has been adding iframe tags in your index files then its probably this kind of attack and the simple solution is to disable the ftp server and go reset every single password on the server+clients. Once done you may re-enable your ftp server.
    Actually I told all my clients to change their passwords (FTP.CP...), maybe some of them done it ,the rest not.

    I think I will do it for them, than I will inform them.
    Yes, I will go with your suggestion.
    My site:
    SMS

  8. #8
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196
    Quote Originally Posted by Vin DSL View Post
    Anybody running Joomla!?!?

    http://www.zone-h.org/index.php?opti...4981&Itemid=92

    Most of the recently reported defacements have been on Linux systems running Joomla - hackers love it!

    Once they get in, they upload a root kit of sorts...

    EDIT

    BTW, if you visit Zone-H (above) look at the number of attacks on Linux vs BSD (top left sidebar)...
    No one running Joomla.
    I will visit Zone-H, maybe I will get some hints.
    My site:
    SMS

  9. #9
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196
    Quote Originally Posted by jason View Post
    I'll throw in my 2 cents in saying that this is either an FTP attack (as thisisit suggests) or a script-exploit attack. If you are running any scripts (such as CMSes, blogs, discussion forums, etc.) check that you are running the newest version of the application and of any plugins you might be using. Very often the attackers go after bugs in these common programs to gain access to your system.

    --Jason
    script-exploit attack !! Y not !

    Sometimes it’s very hard to search for that script or bug among many sites of clients!!
    My site:
    SMS

  10. #10
    Loyal Client rashad's Avatar
    Join Date
    Nov 2006
    Posts
    196
    The strange thing is, he does not change only one index (NO) , actually he changes all the indexes at once !!
    The temporary solution is , I told my clients to go to their forum admin , and change only the style, it works
    My site:
    SMS

  11. #11
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Wild!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  12. #12
    Techinical Support Rep.
    Join Date
    Oct 2008
    Location
    Canada
    Posts
    526
    Quote Originally Posted by rashad View Post
    Hi,
    I have secured my VPS very well, but I do not know how Hacker can change all the indexes for my clients at same time !!

    I searched to see if any file the haker created is hidden on the VPS, however, no luck. Any suggestions on what or where to look to fix this??
    Is there any special script or program can be install to stop this kind of thing?
    If the attacker is changing every site it a the same time then the issue is likely that one of your services that is running with root privileges has been exploited or another service with lesser privileges was exploited and then they used a local root exploit.

    1) Change your root password to something secure:
    http://www.pctools.com/guides/passwo... generate=true

    2) run rkhunter and chkrootkit

    3) check your log files

    If your VPS has been rooted you are best to backup all your files and have support do a fresh install.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •